File 7c6e20f1b08b5437_unicorn-47813.exe

Size 468.1KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b5f04f522a5e86cb21ee5a8cd233a3c3
SHA1 f98862398223a3ee1efa31528b6f61a45aa974d5
SHA256 7c6e20f1b08b5437af55e664e28837b53f5e3ee2d17c85e370bc5a8ce8044ba8
SHA512
d156aff607e3f6fc05f6dcf2b9bd795d77fa1eb80a41da261457e862ecdb09263f15aab8e332a7456de68235c728f1045fbc139513cccbe39bc0bdf7a5d24e16
CRC32 7C1B489F
ssdeep None
Yara
  • SEH__vba - (no description)

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6585883

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 2, 2025, 12:20 p.m. July 2, 2025, 12:30 p.m. 609 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-24 21:38:12,015 [analyzer] DEBUG: Starting analyzer from: C:\tmp4w2pkt
2025-06-24 21:38:12,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\qpoHSgNSGYwWnqifMiXvdwhZMihEN
2025-06-24 21:38:12,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\byQGAAlMVzcUwObmtffzfJIFqAxPGFNL
2025-06-24 21:38:12,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:38:12,030 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:38:12,328 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:38:12,328 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:38:12,717 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:38:12,937 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-24 21:38:12,937 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:38:12,937 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:38:12,937 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:38:12,937 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:38:13,030 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:38:13,030 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:38:13,030 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:38:13,030 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:38:13,187 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\7c6e20f1b08b5437_unicorn-47813.exe' with arguments '' and pid 2820
2025-06-24 21:38:13,405 [analyzer] DEBUG: Loaded monitor into process with pid 2820
2025-06-24 21:38:16,467 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1028.exe
2025-06-24 21:38:16,562 [analyzer] INFO: Injected into process with pid 1860 and name u'Unicorn-1028.exe'
2025-06-24 21:38:16,717 [analyzer] DEBUG: Loaded monitor into process with pid 1860
2025-06-24 21:38:19,780 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52284.exe
2025-06-24 21:38:19,828 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-15890.exe
2025-06-24 21:38:19,858 [analyzer] INFO: Injected into process with pid 3004 and name u'Unicorn-52284.exe'
2025-06-24 21:38:19,905 [analyzer] INFO: Injected into process with pid 292 and name u'Unicorn-15890.exe'
2025-06-24 21:38:20,030 [analyzer] DEBUG: Loaded monitor into process with pid 3004
2025-06-24 21:38:20,078 [analyzer] DEBUG: Loaded monitor into process with pid 292
2025-06-24 21:38:23,108 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55372.exe
2025-06-24 21:38:23,155 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-18978.exe
2025-06-24 21:38:23,187 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19301.exe
2025-06-24 21:38:23,250 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65194.exe
2025-06-24 21:38:23,328 [analyzer] INFO: Injected into process with pid 1260 and name u'Unicorn-55372.exe'
2025-06-24 21:38:23,328 [analyzer] INFO: Injected into process with pid 2108 and name u'Unicorn-18978.exe'
2025-06-24 21:38:23,375 [analyzer] INFO: Injected into process with pid 2404 and name u'Unicorn-65194.exe'
2025-06-24 21:38:23,375 [analyzer] INFO: Injected into process with pid 2812 and name u'Unicorn-19301.exe'
2025-06-24 21:38:23,500 [analyzer] DEBUG: Loaded monitor into process with pid 2108
2025-06-24 21:38:23,515 [analyzer] DEBUG: Loaded monitor into process with pid 2812
2025-06-24 21:38:23,530 [analyzer] DEBUG: Loaded monitor into process with pid 2404
2025-06-24 21:38:23,562 [analyzer] DEBUG: Loaded monitor into process with pid 1260
2025-06-24 21:38:26,703 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41260.exe
2025-06-24 21:38:26,780 [analyzer] INFO: Injected into process with pid 2932 and name u'Unicorn-41260.exe'
2025-06-24 21:38:26,812 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31730.exe
2025-06-24 21:38:26,890 [analyzer] INFO: Injected into process with pid 2956 and name u'Unicorn-31730.exe'
2025-06-24 21:38:26,953 [analyzer] DEBUG: Loaded monitor into process with pid 2932
2025-06-24 21:38:26,953 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40492.exe
2025-06-24 21:38:27,000 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27036.exe
2025-06-24 21:38:27,046 [analyzer] DEBUG: Loaded monitor into process with pid 2956
2025-06-24 21:38:27,092 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43180.exe
2025-06-24 21:38:27,140 [analyzer] INFO: Injected into process with pid 712 and name u'Unicorn-40492.exe'
2025-06-24 21:38:27,155 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-36443.exe
2025-06-24 21:38:27,171 [analyzer] INFO: Injected into process with pid 2240 and name u'Unicorn-27036.exe'
2025-06-24 21:38:27,217 [analyzer] INFO: Injected into process with pid 2348 and name u'Unicorn-43180.exe'
2025-06-24 21:38:27,296 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58675.exe
2025-06-24 21:38:27,296 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39074.exe
2025-06-24 21:38:27,328 [analyzer] DEBUG: Loaded monitor into process with pid 712
2025-06-24 21:38:27,342 [analyzer] DEBUG: Loaded monitor into process with pid 2240
2025-06-24 21:38:27,342 [analyzer] INFO: Injected into process with pid 1988 and name u'Unicorn-36443.exe'
2025-06-24 21:38:27,437 [analyzer] DEBUG: Loaded monitor into process with pid 2348
2025-06-24 21:38:27,483 [analyzer] INFO: Injected into process with pid 2360 and name u'Unicorn-58675.exe'
2025-06-24 21:38:27,483 [analyzer] INFO: Injected into process with pid 1840 and name u'Unicorn-39074.exe'
2025-06-24 21:38:27,515 [analyzer] DEBUG: Loaded monitor into process with pid 1988
2025-06-24 21:38:27,640 [analyzer] DEBUG: Loaded monitor into process with pid 2360
2025-06-24 21:38:27,640 [analyzer] DEBUG: Loaded monitor into process with pid 1840
2025-06-24 21:38:30,015 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41333.exe
2025-06-24 21:38:30,092 [analyzer] INFO: Injected into process with pid 3144 and name u'Unicorn-41333.exe'
2025-06-24 21:38:30,140 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21083.exe
2025-06-24 21:38:30,217 [analyzer] INFO: Injected into process with pid 3184 and name u'Unicorn-21083.exe'
2025-06-24 21:38:30,233 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60108.exe
2025-06-24 21:38:30,265 [analyzer] DEBUG: Loaded monitor into process with pid 3144
2025-06-24 21:38:30,328 [analyzer] INFO: Injected into process with pid 3248 and name u'Unicorn-60108.exe'
2025-06-24 21:38:30,390 [analyzer] DEBUG: Loaded monitor into process with pid 3184
2025-06-24 21:38:30,405 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42931.exe
2025-06-24 21:38:30,546 [analyzer] DEBUG: Loaded monitor into process with pid 3248
2025-06-24 21:38:30,546 [analyzer] INFO: Injected into process with pid 3296 and name u'Unicorn-42931.exe'
2025-06-24 21:38:30,703 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45500.exe
2025-06-24 21:38:30,717 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58629.exe
2025-06-24 21:38:30,828 [analyzer] DEBUG: Loaded monitor into process with pid 3296
2025-06-24 21:38:30,842 [analyzer] INFO: Injected into process with pid 3340 and name u'Unicorn-45500.exe'
2025-06-24 21:38:30,875 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57731.exe
2025-06-24 21:38:30,905 [analyzer] INFO: Injected into process with pid 3356 and name u'Unicorn-58629.exe'
2025-06-24 21:38:30,921 [analyzer] INFO: Injected into process with pid 3388 and name u'Unicorn-58629.exe'
2025-06-24 21:38:31,030 [analyzer] DEBUG: Loaded monitor into process with pid 3340
2025-06-24 21:38:31,046 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27554.exe
2025-06-24 21:38:31,046 [analyzer] INFO: Injected into process with pid 3448 and name u'Unicorn-57731.exe'
2025-06-24 21:38:31,062 [analyzer] DEBUG: Loaded monitor into process with pid 3356
2025-06-24 21:38:31,155 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44021.exe
2025-06-24 21:38:31,155 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24155.exe
2025-06-24 21:38:31,155 [analyzer] DEBUG: Loaded monitor into process with pid 3388
2025-06-24 21:38:31,265 [analyzer] INFO: Injected into process with pid 3508 and name u'Unicorn-27554.exe'
2025-06-24 21:38:31,296 [analyzer] INFO: Injected into process with pid 3548 and name u'Unicorn-44021.exe'
2025-06-24 21:38:31,312 [analyzer] DEBUG: Loaded monitor into process with pid 3448
2025-06-24 21:38:31,405 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7465.exe
2025-06-24 21:38:31,421 [analyzer] INFO: Injected into process with pid 3540 and name u'Unicorn-24155.exe'
2025-06-24 21:38:31,421 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13595.exe
2025-06-24 21:38:31,453 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26725.exe
2025-06-24 21:38:31,546 [analyzer] DEBUG: Loaded monitor into process with pid 3508
2025-06-24 21:38:31,592 [analyzer] DEBUG: Loaded monitor into process with pid 3548
2025-06-24 21:38:31,625 [analyzer] DEBUG: Loaded monitor into process with pid 3540
2025-06-24 21:38:31,625 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6969.exe
2025-06-24 21:38:31,640 [analyzer] INFO: Injected into process with pid 3640 and name u'Unicorn-7465.exe'
2025-06-24 21:38:31,655 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42442.exe
2025-06-24 21:38:31,655 [analyzer] INFO: Injected into process with pid 3660 and name u'Unicorn-13595.exe'
2025-06-24 21:38:31,750 [analyzer] INFO: Injected into process with pid 3688 and name u'Unicorn-26725.exe'
2025-06-24 21:38:31,828 [analyzer] INFO: Injected into process with pid 3784 and name u'Unicorn-42442.exe'
2025-06-24 21:38:31,828 [analyzer] INFO: Injected into process with pid 3752 and name u'Unicorn-6969.exe'
2025-06-24 21:38:31,858 [analyzer] DEBUG: Loaded monitor into process with pid 3640
2025-06-24 21:38:31,953 [analyzer] DEBUG: Loaded monitor into process with pid 3688
2025-06-24 21:38:31,967 [analyzer] DEBUG: Loaded monitor into process with pid 3660
2025-06-24 21:38:32,000 [analyzer] DEBUG: Loaded monitor into process with pid 3752
2025-06-24 21:38:32,062 [analyzer] DEBUG: Loaded monitor into process with pid 3784
2025-06-24 21:38:33,328 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23980.exe
2025-06-24 21:38:33,592 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6418.exe
2025-06-24 21:38:33,592 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26284.exe
2025-06-24 21:38:33,592 [analyzer] INFO: Injected into process with pid 3904 and name u'Unicorn-23980.exe'
2025-06-24 21:38:33,765 [analyzer] INFO: Injected into process with pid 3940 and name u'Unicorn-6418.exe'
2025-06-24 21:38:33,780 [analyzer] INFO: Injected into process with pid 3948 and name u'Unicorn-26284.exe'
2025-06-24 21:38:33,796 [analyzer] DEBUG: Loaded monitor into process with pid 3904
2025-06-24 21:38:33,812 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34.exe
2025-06-24 21:38:33,967 [analyzer] DEBUG: Loaded monitor into process with pid 3940
2025-06-24 21:38:33,983 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25132.exe
2025-06-24 21:38:34,000 [analyzer] DEBUG: Loaded monitor into process with pid 3948
2025-06-24 21:38:34,125 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48204.exe
2025-06-24 21:38:34,155 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19730.exe
2025-06-24 21:38:34,187 [analyzer] INFO: Injected into process with pid 4024 and name u'Unicorn-34.exe'
2025-06-24 21:38:34,405 [analyzer] INFO: Injected into process with pid 4068 and name u'Unicorn-25132.exe'
2025-06-24 21:38:34,421 [analyzer] INFO: Injected into process with pid 4092 and name u'Unicorn-48204.exe'
2025-06-24 21:38:34,500 [analyzer] DEBUG: Loaded monitor into process with pid 4024
2025-06-24 21:38:34,655 [analyzer] INFO: Injected into process with pid 2192 and name u'Unicorn-19730.exe'
2025-06-24 21:38:34,671 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10331.exe
2025-06-24 21:38:34,780 [analyzer] DEBUG: Loaded monitor into process with pid 4092
2025-06-24 21:38:34,842 [analyzer] DEBUG: Loaded monitor into process with pid 4068
2025-06-24 21:38:34,858 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2025-06-24 21:38:35,046 [analyzer] INFO: Injected into process with pid 3220 and name u'Unicorn-10331.exe'
2025-06-24 21:38:35,233 [analyzer] DEBUG: Loaded monitor into process with pid 3220
2025-06-24 21:38:35,358 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50508.exe
2025-06-24 21:38:35,500 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50124.exe
2025-06-24 21:38:35,796 [analyzer] INFO: Injected into process with pid 3324 and name u'Unicorn-50508.exe'
2025-06-24 21:38:35,796 [analyzer] INFO: Injected into process with pid 3396 and name u'Unicorn-50124.exe'
2025-06-24 21:38:35,967 [analyzer] DEBUG: Loaded monitor into process with pid 3324
2025-06-24 21:38:36,796 [analyzer] DEBUG: Loaded monitor into process with pid 3396
2025-06-24 21:38:36,812 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20331.exe
2025-06-24 21:38:36,828 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34066.exe
2025-06-24 21:38:36,828 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39932.exe
2025-06-24 21:38:36,842 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55827.exe
2025-06-24 21:38:36,842 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10155.exe
2025-06-24 21:38:36,858 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40197.exe
2025-06-24 21:38:36,858 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40197.exe
2025-06-24 21:38:36,858 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40197.exe
2025-06-24 21:38:37,030 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61852.exe
2025-06-24 21:38:37,125 [analyzer] INFO: Injected into process with pid 3580 and name u'Unicorn-39932.exe'
2025-06-24 21:38:37,140 [analyzer] INFO: Injected into process with pid 3592 and name u'Unicorn-55827.exe'
2025-06-24 21:38:37,140 [analyzer] INFO: Injected into process with pid 3584 and name u'Unicorn-20331.exe'
2025-06-24 21:38:37,171 [analyzer] INFO: Injected into process with pid 3560 and name u'Unicorn-34066.exe'
2025-06-24 21:38:37,171 [analyzer] INFO: Injected into process with pid 3604 and name u'Unicorn-10155.exe'
2025-06-24 21:38:37,171 [analyzer] INFO: Injected into process with pid 3736 and name u'Unicorn-40197.exe'
2025-06-24 21:38:37,203 [analyzer] INFO: Injected into process with pid 3900 and name u'Unicorn-61852.exe'
2025-06-24 21:38:37,328 [analyzer] DEBUG: Loaded monitor into process with pid 3592
2025-06-24 21:38:37,328 [analyzer] DEBUG: Loaded monitor into process with pid 3580
2025-06-24 21:38:37,358 [analyzer] DEBUG: Loaded monitor into process with pid 3604
2025-06-24 21:38:37,390 [analyzer] DEBUG: Loaded monitor into process with pid 3900
2025-06-24 21:38:37,390 [analyzer] DEBUG: Loaded monitor into process with pid 3584
2025-06-24 21:38:37,390 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24821.exe
2025-06-24 21:38:37,421 [analyzer] DEBUG: Loaded monitor into process with pid 3736
2025-06-24 21:38:37,483 [analyzer] DEBUG: Loaded monitor into process with pid 3560
2025-06-24 21:38:37,717 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59283.exe
2025-06-24 21:38:37,733 [analyzer] INFO: Injected into process with pid 3352 and name u'Unicorn-24821.exe'
2025-06-24 21:38:37,905 [analyzer] DEBUG: Loaded monitor into process with pid 3352
2025-06-24 21:38:38,296 [analyzer] INFO: Injected into process with pid 3748 and name u'Unicorn-59283.exe'
2025-06-24 21:38:38,296 [analyzer] INFO: Injected into process with pid 3800 and name u'Unicorn-59283.exe'
2025-06-24 21:38:38,390 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35148.exe
2025-06-24 21:38:38,390 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42531.exe
2025-06-24 21:38:38,390 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23195.exe
2025-06-24 21:38:38,515 [analyzer] DEBUG: Loaded monitor into process with pid 3748
2025-06-24 21:38:38,578 [analyzer] DEBUG: Loaded monitor into process with pid 3800
2025-06-24 21:38:39,046 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13698.exe
2025-06-24 21:38:39,046 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19829.exe
2025-06-24 21:38:39,467 [analyzer] INFO: Injected into process with pid 4000 and name u'Unicorn-23195.exe'
2025-06-24 21:38:39,483 [analyzer] INFO: Injected into process with pid 3936 and name u'Unicorn-35148.exe'
2025-06-24 21:38:39,562 [analyzer] INFO: Injected into process with pid 4016 and name u'Unicorn-42531.exe'
2025-06-24 21:38:39,562 [analyzer] INFO: Injected into process with pid 3804 and name u'Unicorn-19829.exe'
2025-06-24 21:38:39,562 [analyzer] INFO: Injected into process with pid 3792 and name u'Unicorn-13698.exe'
2025-06-24 21:38:39,733 [analyzer] DEBUG: Loaded monitor into process with pid 4000
2025-06-24 21:38:39,780 [analyzer] DEBUG: Loaded monitor into process with pid 3804
2025-06-24 21:38:39,796 [analyzer] DEBUG: Loaded monitor into process with pid 3936
2025-06-24 21:38:39,842 [analyzer] DEBUG: Loaded monitor into process with pid 3792
2025-06-24 21:38:39,905 [analyzer] DEBUG: Loaded monitor into process with pid 4016
2025-06-24 21:38:39,967 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52371.exe
2025-06-24 21:38:40,015 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19506.exe
2025-06-24 21:38:40,015 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19506.exe
2025-06-24 21:38:40,217 [analyzer] INFO: Injected into process with pid 4224 and name u'Unicorn-52371.exe'
2025-06-24 21:38:40,233 [analyzer] INFO: Injected into process with pid 4248 and name u'Unicorn-19506.exe'
2025-06-24 21:38:40,405 [analyzer] DEBUG: Loaded monitor into process with pid 4248
2025-06-24 21:38:40,467 [analyzer] DEBUG: Loaded monitor into process with pid 4224
2025-06-24 21:38:40,467 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40968.exe
2025-06-24 21:38:40,671 [analyzer] INFO: Injected into process with pid 4312 and name u'Unicorn-40968.exe'
2025-06-24 21:38:40,842 [analyzer] DEBUG: Loaded monitor into process with pid 4312
2025-06-24 21:38:42,640 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1118.exe
2025-06-24 21:38:42,780 [analyzer] INFO: Injected into process with pid 4404 and name u'Unicorn-1118.exe'
2025-06-24 21:38:43,000 [analyzer] DEBUG: Loaded monitor into process with pid 4404
2025-06-24 21:38:43,046 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54599.exe
2025-06-24 21:38:43,171 [analyzer] INFO: Injected into process with pid 4476 and name u'Unicorn-54599.exe'
2025-06-24 21:38:43,312 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54808.exe
2025-06-24 21:38:43,342 [analyzer] DEBUG: Loaded monitor into process with pid 4476
2025-06-24 21:38:43,437 [analyzer] INFO: Injected into process with pid 4520 and name u'Unicorn-54808.exe'
2025-06-24 21:38:43,608 [analyzer] DEBUG: Loaded monitor into process with pid 4520
2025-06-24 21:38:43,812 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6878.exe
2025-06-24 21:38:43,937 [analyzer] INFO: Injected into process with pid 4564 and name u'Unicorn-6878.exe'
2025-06-24 21:38:44,125 [analyzer] DEBUG: Loaded monitor into process with pid 4564
2025-06-24 21:38:44,858 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30600.exe
2025-06-24 21:38:45,171 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-231.exe
2025-06-24 21:38:45,171 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-231.exe
2025-06-24 21:38:45,171 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10245.exe
2025-06-24 21:38:45,187 [analyzer] INFO: Injected into process with pid 4608 and name u'Unicorn-30600.exe'
2025-06-24 21:38:45,390 [analyzer] DEBUG: Loaded monitor into process with pid 4608
2025-06-24 21:38:45,405 [analyzer] INFO: Injected into process with pid 4652 and name u'Unicorn-10245.exe'
2025-06-24 21:38:45,405 [analyzer] INFO: Injected into process with pid 4644 and name u'Unicorn-231.exe'
2025-06-24 21:38:45,437 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42150.exe
2025-06-24 21:38:45,592 [analyzer] DEBUG: Loaded monitor into process with pid 4644
2025-06-24 21:38:45,608 [analyzer] DEBUG: Loaded monitor into process with pid 4652
2025-06-24 21:38:45,717 [analyzer] INFO: Injected into process with pid 4732 and name u'Unicorn-42150.exe'
2025-06-24 21:38:45,796 [analyzer] INFO: Injected into process with pid 4724 and name u'Unicorn-42150.exe'
2025-06-24 21:38:45,875 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-999.exe
2025-06-24 21:38:46,015 [analyzer] DEBUG: Loaded monitor into process with pid 4732
2025-06-24 21:38:46,046 [analyzer] DEBUG: Loaded monitor into process with pid 4724
2025-06-24 21:38:46,092 [analyzer] INFO: Injected into process with pid 4816 and name u'Unicorn-999.exe'
2025-06-24 21:38:46,092 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28576.exe
2025-06-24 21:38:46,296 [analyzer] INFO: Injected into process with pid 4864 and name u'Unicorn-28576.exe'
2025-06-24 21:38:46,358 [analyzer] DEBUG: Loaded monitor into process with pid 4816
2025-06-24 21:38:46,483 [analyzer] DEBUG: Loaded monitor into process with pid 4864
2025-06-24 21:38:46,858 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24456.exe
2025-06-24 21:38:46,858 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42415.exe
2025-06-24 21:38:47,608 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33184.exe
2025-06-24 21:38:47,608 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13583.exe
2025-06-24 21:38:47,608 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13583.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,625 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33449.exe
2025-06-24 21:38:47,717 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-319.exe
2025-06-24 21:38:47,765 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59607.exe
2025-06-24 21:38:47,905 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56671.exe
2025-06-24 21:38:47,953 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48825.exe
2025-06-24 21:38:47,953 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23806.exe
2025-06-24 21:38:47,967 [analyzer] INFO: Injected into process with pid 4916 and name u'Unicorn-24456.exe'
2025-06-24 21:38:48,000 [analyzer] INFO: Injected into process with pid 4924 and name u'Unicorn-42415.exe'
2025-06-24 21:38:48,187 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6552.exe
2025-06-24 21:38:48,296 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-631.exe
2025-06-24 21:38:48,342 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27173.exe
2025-06-24 21:38:48,342 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7838.exe
2025-06-24 21:38:48,358 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29774.exe
2025-06-24 21:38:48,375 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33304.exe
2025-06-24 21:38:48,467 [analyzer] INFO: Injected into process with pid 4992 and name u'Unicorn-33449.exe'
2025-06-24 21:38:48,500 [analyzer] INFO: Injected into process with pid 4984 and name u'Unicorn-13583.exe'
2025-06-24 21:38:48,515 [analyzer] INFO: Injected into process with pid 4976 and name u'Unicorn-33184.exe'
2025-06-24 21:38:48,515 [analyzer] DEBUG: Loaded monitor into process with pid 4916
2025-06-24 21:38:48,546 [analyzer] INFO: Injected into process with pid 5088 and name u'Unicorn-59607.exe'
2025-06-24 21:38:48,546 [analyzer] INFO: Injected into process with pid 5028 and name u'Unicorn-319.exe'
2025-06-24 21:38:48,578 [analyzer] DEBUG: Loaded monitor into process with pid 4924
2025-06-24 21:38:48,578 [analyzer] INFO: Injected into process with pid 3476 and name u'Unicorn-56671.exe'
2025-06-24 21:38:48,828 [analyzer] INFO: Injected into process with pid 4104 and name u'Unicorn-23806.exe'
2025-06-24 21:38:48,828 [analyzer] INFO: Injected into process with pid 3776 and name u'Unicorn-48825.exe'
2025-06-24 21:38:48,828 [analyzer] DEBUG: Loaded monitor into process with pid 4992
2025-06-24 21:38:48,921 [analyzer] DEBUG: Loaded monitor into process with pid 4976
2025-06-24 21:38:48,983 [analyzer] DEBUG: Loaded monitor into process with pid 4984
2025-06-24 21:38:49,030 [analyzer] DEBUG: Loaded monitor into process with pid 5088
2025-06-24 21:38:49,217 [analyzer] DEBUG: Loaded monitor into process with pid 5028
2025-06-24 21:38:49,217 [analyzer] INFO: Injected into process with pid 4240 and name u'Unicorn-6552.exe'
2025-06-24 21:38:49,217 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5903.exe
2025-06-24 21:38:49,217 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5903.exe
2025-06-24 21:38:49,233 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25769.exe
2025-06-24 21:38:49,233 [analyzer] DEBUG: Loaded monitor into process with pid 3476
2025-06-24 21:38:49,265 [analyzer] INFO: Injected into process with pid 4332 and name u'Unicorn-631.exe'
2025-06-24 21:38:49,296 [analyzer] INFO: Injected into process with pid 4416 and name u'Unicorn-29774.exe'
2025-06-24 21:38:49,312 [analyzer] INFO: Injected into process with pid 1816 and name u'Unicorn-27173.exe'
2025-06-24 21:38:49,358 [analyzer] INFO: Injected into process with pid 2056 and name u'Unicorn-7838.exe'
2025-06-24 21:38:49,375 [analyzer] INFO: Injected into process with pid 4436 and name u'Unicorn-33304.exe'
2025-06-24 21:38:49,390 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54144.exe
2025-06-24 21:38:49,405 [analyzer] DEBUG: Loaded monitor into process with pid 3776
2025-06-24 21:38:49,405 [analyzer] DEBUG: Loaded monitor into process with pid 4104
2025-06-24 21:38:49,421 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-8472.exe
2025-06-24 21:38:49,515 [analyzer] DEBUG: Loaded monitor into process with pid 4240
2025-06-24 21:38:49,530 [analyzer] DEBUG: Loaded monitor into process with pid 4332
2025-06-24 21:38:49,546 [analyzer] DEBUG: Loaded monitor into process with pid 1816
2025-06-24 21:38:49,608 [analyzer] DEBUG: Loaded monitor into process with pid 4416
2025-06-24 21:38:49,608 [analyzer] INFO: Injected into process with pid 3712 and name u'Unicorn-5903.exe'
2025-06-24 21:38:49,608 [analyzer] INFO: Injected into process with pid 5024 and name u'Unicorn-25769.exe'
2025-06-24 21:38:49,625 [analyzer] DEBUG: Loaded monitor into process with pid 2056
2025-06-24 21:38:49,717 [analyzer] INFO: Injected into process with pid 4152 and name u'Unicorn-8472.exe'
2025-06-24 21:38:49,717 [analyzer] INFO: Injected into process with pid 4180 and name u'Unicorn-54144.exe'
2025-06-24 21:38:49,717 [analyzer] DEBUG: Loaded monitor into process with pid 4436
2025-06-24 21:38:49,828 [analyzer] DEBUG: Loaded monitor into process with pid 5024
2025-06-24 21:38:49,890 [analyzer] DEBUG: Loaded monitor into process with pid 3712
2025-06-24 21:38:50,000 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58825.exe
2025-06-24 21:38:50,078 [analyzer] DEBUG: Loaded monitor into process with pid 4152
2025-06-24 21:38:50,140 [analyzer] DEBUG: Loaded monitor into process with pid 4180
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19375.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10710.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13510.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65312.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13510.exe
2025-06-24 21:38:54,453 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13510.exe
2025-06-24 21:38:54,530 [analyzer] INFO: Injected into process with pid 5004 and name u'Unicorn-58825.exe'
2025-06-24 21:38:55,717 [analyzer] DEBUG: Loaded monitor into process with pid 5004
2025-06-24 21:38:56,171 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-15566.exe
2025-06-24 21:38:56,187 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38633.exe
2025-06-24 21:38:56,280 [analyzer] INFO: Injected into process with pid 5132 and name u'Unicorn-13510.exe'
2025-06-24 21:38:56,312 [analyzer] INFO: Injected into process with pid 5124 and name u'Unicorn-65312.exe'
2025-06-24 21:38:56,312 [analyzer] INFO: Injected into process with pid 2912 and name u'Unicorn-19375.exe'
2025-06-24 21:38:56,342 [analyzer] INFO: Injected into process with pid 4972 and name u'Unicorn-10710.exe'
2025-06-24 21:38:56,342 [analyzer] INFO: Injected into process with pid 5140 and name u'Unicorn-13510.exe'
2025-06-24 21:38:56,500 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41112.exe
2025-06-24 21:38:56,562 [analyzer] DEBUG: Loaded monitor into process with pid 2912
2025-06-24 21:38:56,592 [analyzer] DEBUG: Loaded monitor into process with pid 5124
2025-06-24 21:38:56,608 [analyzer] INFO: Injected into process with pid 5292 and name u'Unicorn-15566.exe'
2025-06-24 21:38:56,608 [analyzer] INFO: Injected into process with pid 5300 and name u'Unicorn-38633.exe'
2025-06-24 21:38:56,625 [analyzer] DEBUG: Loaded monitor into process with pid 5132
2025-06-24 21:38:56,671 [analyzer] DEBUG: Loaded monitor into process with pid 4972
2025-06-24 21:38:56,733 [analyzer] DEBUG: Loaded monitor into process with pid 5140
2025-06-24 21:38:57,078 [analyzer] DEBUG: Loaded monitor into process with pid 5300
2025-06-24 21:38:57,092 [analyzer] INFO: Injected into process with pid 5376 and name u'Unicorn-41112.exe'
2025-06-24 21:38:57,108 [analyzer] DEBUG: Loaded monitor into process with pid 5292
2025-06-24 21:38:57,312 [analyzer] DEBUG: Loaded monitor into process with pid 5376
2025-06-24 21:38:57,625 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46607.exe
2025-06-24 21:38:57,640 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40742.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47967.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2030.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61702.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61702.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47967.exe
2025-06-24 21:38:58,405 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58902.exe
2025-06-24 21:38:58,421 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61702.exe
2025-06-24 21:38:58,515 [analyzer] INFO: Injected into process with pid 5524 and name u'Unicorn-40742.exe'
2025-06-24 21:38:58,515 [analyzer] INFO: Injected into process with pid 5532 and name u'Unicorn-40742.exe'
2025-06-24 21:38:58,530 [analyzer] INFO: Injected into process with pid 5492 and name u'Unicorn-40742.exe'
2025-06-24 21:38:58,530 [analyzer] INFO: Injected into process with pid 5484 and name u'Unicorn-46607.exe'
2025-06-24 21:38:58,875 [analyzer] DEBUG: Loaded monitor into process with pid 5532
2025-06-24 21:38:58,983 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-110.exe
2025-06-24 21:38:59,000 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19976.exe
2025-06-24 21:38:59,140 [analyzer] DEBUG: Loaded monitor into process with pid 5492
2025-06-24 21:38:59,171 [analyzer] INFO: Injected into process with pid 5636 and name u'Unicorn-2030.exe'
2025-06-24 21:38:59,203 [analyzer] DEBUG: Loaded monitor into process with pid 5524
2025-06-24 21:38:59,203 [analyzer] INFO: Injected into process with pid 5664 and name u'Unicorn-61702.exe'
2025-06-24 21:38:59,233 [analyzer] DEBUG: Loaded monitor into process with pid 5484
2025-06-24 21:38:59,233 [analyzer] INFO: Injected into process with pid 5656 and name u'Unicorn-58902.exe'
2025-06-24 21:38:59,437 [analyzer] INFO: Injected into process with pid 5672 and name u'Unicorn-47967.exe'
2025-06-24 21:38:59,437 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10255.exe
2025-06-24 21:38:59,467 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56192.exe
2025-06-24 21:38:59,483 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54111.exe
2025-06-24 21:38:59,640 [analyzer] DEBUG: Loaded monitor into process with pid 5664
2025-06-24 21:38:59,655 [analyzer] DEBUG: Loaded monitor into process with pid 5636
2025-06-24 21:38:59,687 [analyzer] DEBUG: Loaded monitor into process with pid 5656
2025-06-24 21:38:59,842 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57064.exe
2025-06-24 21:38:59,858 [analyzer] INFO: Injected into process with pid 5800 and name u'Unicorn-19976.exe'
2025-06-24 21:38:59,858 [analyzer] INFO: Injected into process with pid 5792 and name u'Unicorn-110.exe'
2025-06-24 21:38:59,983 [analyzer] DEBUG: Loaded monitor into process with pid 5672
2025-06-24 21:39:00,030 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42974.exe
2025-06-24 21:39:00,062 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53910.exe
2025-06-24 21:39:00,171 [analyzer] DEBUG: Loaded monitor into process with pid 5800
2025-06-24 21:39:00,203 [analyzer] INFO: Injected into process with pid 5892 and name u'Unicorn-10255.exe'
2025-06-24 21:39:00,217 [analyzer] INFO: Injected into process with pid 5900 and name u'Unicorn-56192.exe'
2025-06-24 21:39:00,233 [analyzer] DEBUG: Loaded monitor into process with pid 5792
2025-06-24 21:39:00,233 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29592.exe
2025-06-24 21:39:00,358 [analyzer] INFO: Injected into process with pid 5920 and name u'Unicorn-54111.exe'
2025-06-24 21:39:00,562 [analyzer] DEBUG: Loaded monitor into process with pid 5892
2025-06-24 21:39:00,608 [analyzer] DEBUG: Loaded monitor into process with pid 5900
2025-06-24 21:39:00,608 [analyzer] INFO: Injected into process with pid 6000 and name u'Unicorn-57064.exe'
2025-06-24 21:39:00,750 [analyzer] DEBUG: Loaded monitor into process with pid 5920
2025-06-24 21:39:00,953 [analyzer] INFO: Injected into process with pid 6056 and name u'Unicorn-42974.exe'
2025-06-24 21:39:00,967 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35248.exe
2025-06-24 21:39:00,967 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30095.exe
2025-06-24 21:39:01,030 [analyzer] INFO: Injected into process with pid 6064 and name u'Unicorn-53910.exe'
2025-06-24 21:39:01,125 [analyzer] DEBUG: Loaded monitor into process with pid 6000
2025-06-24 21:39:01,250 [analyzer] DEBUG: Loaded monitor into process with pid 6056
2025-06-24 21:39:01,265 [analyzer] INFO: Injected into process with pid 6136 and name u'Unicorn-29592.exe'
2025-06-24 21:39:01,390 [analyzer] INFO: Injected into process with pid 5256 and name u'Unicorn-35248.exe'
2025-06-24 21:39:01,390 [analyzer] INFO: Injected into process with pid 5272 and name u'Unicorn-30095.exe'
2025-06-24 21:39:01,405 [analyzer] DEBUG: Loaded monitor into process with pid 6064
2025-06-24 21:39:01,500 [analyzer] DEBUG: Loaded monitor into process with pid 6136
2025-06-24 21:39:01,515 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-14390.exe
2025-06-24 21:39:01,515 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6799.exe
2025-06-24 21:39:01,515 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6799.exe
2025-06-24 21:39:01,562 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-14718.exe
2025-06-24 21:39:01,562 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28453.exe
2025-06-24 21:39:01,655 [analyzer] DEBUG: Loaded monitor into process with pid 5256
2025-06-24 21:39:01,671 [analyzer] DEBUG: Loaded monitor into process with pid 5272
2025-06-24 21:39:01,812 [analyzer] INFO: Injected into process with pid 5508 and name u'Unicorn-14390.exe'
2025-06-24 21:39:02,046 [analyzer] INFO: Injected into process with pid 5568 and name u'Unicorn-6799.exe'
2025-06-24 21:39:02,078 [analyzer] INFO: Injected into process with pid 5560 and name u'Unicorn-14718.exe'
2025-06-24 21:39:02,125 [analyzer] INFO: Injected into process with pid 596 and name u'Unicorn-28453.exe'
2025-06-24 21:39:02,140 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41599.exe
2025-06-24 21:39:02,155 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55335.exe
2025-06-24 21:39:02,155 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61200.exe
2025-06-24 21:39:02,155 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52535.exe
2025-06-24 21:39:02,328 [analyzer] DEBUG: Loaded monitor into process with pid 5508
2025-06-24 21:39:02,375 [analyzer] DEBUG: Loaded monitor into process with pid 596
2025-06-24 21:39:02,437 [analyzer] DEBUG: Loaded monitor into process with pid 5560
2025-06-24 21:39:02,453 [analyzer] DEBUG: Loaded monitor into process with pid 5568
2025-06-24 21:39:02,625 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5062.exe
2025-06-24 21:39:02,640 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13992.exe
2025-06-24 21:39:02,687 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51718.exe
2025-06-24 21:39:02,750 [analyzer] INFO: Injected into process with pid 5972 and name u'Unicorn-52535.exe'
2025-06-24 21:39:02,750 [analyzer] INFO: Injected into process with pid 5780 and name u'Unicorn-41599.exe'
2025-06-24 21:39:02,828 [analyzer] INFO: Injected into process with pid 5936 and name u'Unicorn-55335.exe'
2025-06-24 21:39:02,828 [analyzer] INFO: Injected into process with pid 5844 and name u'Unicorn-61200.exe'
2025-06-24 21:39:02,828 [analyzer] INFO: Injected into process with pid 5836 and name u'Unicorn-55335.exe'
2025-06-24 21:39:02,828 [analyzer] INFO: Injected into process with pid 5980 and name u'Unicorn-52535.exe'
2025-06-24 21:39:02,875 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26031.exe
2025-06-24 21:39:02,937 [analyzer] INFO: Injected into process with pid 5504 and name u'Unicorn-13992.exe'
2025-06-24 21:39:02,953 [analyzer] INFO: Injected into process with pid 5516 and name u'Unicorn-5062.exe'
2025-06-24 21:39:02,967 [analyzer] DEBUG: Loaded monitor into process with pid 5780
2025-06-24 21:39:03,030 [analyzer] DEBUG: Loaded monitor into process with pid 5972
2025-06-24 21:39:03,062 [analyzer] DEBUG: Loaded monitor into process with pid 5980
2025-06-24 21:39:03,108 [analyzer] DEBUG: Loaded monitor into process with pid 5836
2025-06-24 21:39:03,125 [analyzer] DEBUG: Loaded monitor into process with pid 5936
2025-06-24 21:39:03,187 [analyzer] DEBUG: Loaded monitor into process with pid 5844
2025-06-24 21:39:03,217 [analyzer] INFO: Injected into process with pid 5652 and name u'Unicorn-51718.exe'
2025-06-24 21:39:03,296 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58023.exe
2025-06-24 21:39:03,296 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44288.exe
2025-06-24 21:39:03,296 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27951.exe
2025-06-24 21:39:03,296 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63888.exe
2025-06-24 21:39:03,312 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44288.exe
2025-06-24 21:39:03,312 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55753.exe
2025-06-24 21:39:03,437 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38750.exe
2025-06-24 21:39:03,437 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52486.exe
2025-06-24 21:39:03,437 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52486.exe
2025-06-24 21:39:03,437 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38750.exe
2025-06-24 21:39:03,467 [analyzer] DEBUG: Loaded monitor into process with pid 5504
2025-06-24 21:39:03,546 [analyzer] DEBUG: Loaded monitor into process with pid 5516
2025-06-24 21:39:03,625 [analyzer] DEBUG: Loaded monitor into process with pid 5652
2025-06-24 21:39:03,937 [analyzer] INFO: Injected into process with pid 6088 and name u'Unicorn-26031.exe'
2025-06-24 21:39:04,046 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13910.exe
2025-06-24 21:39:04,140 [analyzer] INFO: Injected into process with pid 5356 and name u'Unicorn-27951.exe'
2025-06-24 21:39:04,140 [analyzer] INFO: Injected into process with pid 5840 and name u'Unicorn-55753.exe'
2025-06-24 21:39:04,171 [analyzer] INFO: Injected into process with pid 5860 and name u'Unicorn-44288.exe'
2025-06-24 21:39:04,171 [analyzer] INFO: Injected into process with pid 5696 and name u'Unicorn-63888.exe'
2025-06-24 21:39:04,187 [analyzer] DEBUG: Loaded monitor into process with pid 6088
2025-06-24 21:39:04,250 [analyzer] INFO: Injected into process with pid 6164 and name u'Unicorn-38750.exe'
2025-06-24 21:39:04,250 [analyzer] INFO: Injected into process with pid 6176 and name u'Unicorn-52486.exe'
2025-06-24 21:39:04,265 [analyzer] INFO: Injected into process with pid 5688 and name u'Unicorn-58023.exe'
2025-06-24 21:39:04,437 [analyzer] DEBUG: Loaded monitor into process with pid 5840
2025-06-24 21:39:04,453 [analyzer] DEBUG: Loaded monitor into process with pid 5860
2025-06-24 21:39:04,453 [analyzer] INFO: Injected into process with pid 6328 and name u'Unicorn-13910.exe'
2025-06-24 21:39:04,687 [analyzer] DEBUG: Loaded monitor into process with pid 5356
2025-06-24 21:39:04,687 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21689.exe
2025-06-24 21:39:04,687 [analyzer] DEBUG: Loaded monitor into process with pid 5688
2025-06-24 21:39:04,687 [analyzer] DEBUG: Loaded monitor into process with pid 6176
2025-06-24 21:39:04,703 [analyzer] DEBUG: Loaded monitor into process with pid 6164
2025-06-24 21:39:04,717 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64071.exe
2025-06-24 21:39:04,812 [analyzer] DEBUG: Loaded monitor into process with pid 5696
2025-06-24 21:39:04,875 [analyzer] DEBUG: Loaded monitor into process with pid 6328
2025-06-24 21:39:05,265 [analyzer] INFO: Injected into process with pid 6448 and name u'Unicorn-21689.exe'
2025-06-24 21:39:05,280 [analyzer] INFO: Injected into process with pid 6460 and name u'Unicorn-64071.exe'
2025-06-24 21:39:05,328 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52856.exe
2025-06-24 21:39:05,515 [analyzer] DEBUG: Loaded monitor into process with pid 6448
2025-06-24 21:39:05,530 [analyzer] DEBUG: Loaded monitor into process with pid 6460
2025-06-24 21:39:10,717 [analyzer] INFO: Injected into process with pid 6536 and name u'Unicorn-52856.exe'
2025-06-24 21:39:10,780 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7422.exe
2025-06-24 21:39:10,780 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7422.exe
2025-06-24 21:39:10,796 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32623.exe
2025-06-24 21:39:10,796 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26757.exe
2025-06-24 21:39:10,796 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26757.exe
2025-06-24 21:39:10,812 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13022.exe
2025-06-24 21:39:11,015 [analyzer] DEBUG: Loaded monitor into process with pid 6536
2025-06-24 21:39:11,092 [analyzer] INFO: Injected into process with pid 6636 and name u'Unicorn-7422.exe'
2025-06-24 21:39:11,092 [analyzer] INFO: Injected into process with pid 6652 and name u'Unicorn-32623.exe'
2025-06-24 21:39:11,092 [analyzer] INFO: Injected into process with pid 6676 and name u'Unicorn-13022.exe'
2025-06-24 21:39:11,092 [analyzer] INFO: Injected into process with pid 6660 and name u'Unicorn-26757.exe'
2025-06-24 21:39:11,171 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34808.exe
2025-06-24 21:39:11,312 [analyzer] DEBUG: Loaded monitor into process with pid 6652
2025-06-24 21:39:11,312 [analyzer] DEBUG: Loaded monitor into process with pid 6660
2025-06-24 21:39:11,358 [analyzer] DEBUG: Loaded monitor into process with pid 6636
2025-06-24 21:39:11,437 [analyzer] DEBUG: Loaded monitor into process with pid 6676
2025-06-24 21:39:18,375 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28480.exe
2025-06-24 21:39:18,375 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-36681.exe
2025-06-24 21:39:18,375 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20344.exe
2025-06-24 21:39:20,140 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48656.exe
2025-06-24 21:39:20,140 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48656.exe
2025-06-24 21:39:20,140 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42791.exe
2025-06-24 21:39:20,155 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46535.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41382.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32806.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16470.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16470.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38672.exe
2025-06-24 21:39:20,171 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38672.exe
2025-06-24 21:39:20,187 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30006.exe
2025-06-24 21:39:20,187 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30006.exe
2025-06-24 21:39:20,187 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13471.exe
2025-06-24 21:39:20,328 [analyzer] INFO: Injected into process with pid 6808 and name u'Unicorn-34808.exe'
2025-06-24 21:39:20,358 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62679.exe
2025-06-24 21:39:20,358 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33519.exe
2025-06-24 21:39:20,390 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59942.exe
2025-06-24 21:39:20,390 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41678.exe
2025-06-24 21:39:20,421 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51744.exe
2025-06-24 21:39:20,421 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51744.exe
2025-06-24 21:39:21,000 [analyzer] DEBUG: Loaded monitor into process with pid 6808
2025-06-24 21:39:21,030 [analyzer] INFO: Injected into process with pid 6880 and name u'Unicorn-36681.exe'
2025-06-24 21:39:21,030 [analyzer] INFO: Injected into process with pid 6888 and name u'Unicorn-28480.exe'
2025-06-24 21:39:21,030 [analyzer] INFO: Injected into process with pid 6896 and name u'Unicorn-20344.exe'
2025-06-24 21:39:21,125 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60783.exe
2025-06-24 21:39:21,125 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-846.exe
2025-06-24 21:39:21,125 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-14581.exe
2025-06-24 21:39:21,250 [analyzer] INFO: Injected into process with pid 7016 and name u'Unicorn-13471.exe'
2025-06-24 21:39:21,265 [analyzer] INFO: Injected into process with pid 6996 and name u'Unicorn-41382.exe'
2025-06-24 21:39:21,265 [analyzer] INFO: Injected into process with pid 7024 and name u'Unicorn-38672.exe'
2025-06-24 21:39:21,280 [analyzer] INFO: Injected into process with pid 6980 and name u'Unicorn-46535.exe'
2025-06-24 21:39:21,280 [analyzer] INFO: Injected into process with pid 6972 and name u'Unicorn-42791.exe'
2025-06-24 21:39:21,280 [analyzer] INFO: Injected into process with pid 6988 and name u'Unicorn-30006.exe'
2025-06-24 21:39:21,296 [analyzer] INFO: Injected into process with pid 7004 and name u'Unicorn-16470.exe'
2025-06-24 21:39:21,312 [analyzer] DEBUG: Loaded monitor into process with pid 6880
2025-06-24 21:39:21,312 [analyzer] INFO: Injected into process with pid 7032 and name u'Unicorn-32806.exe'
2025-06-24 21:39:21,328 [analyzer] DEBUG: Loaded monitor into process with pid 6888
2025-06-24 21:39:21,328 [analyzer] INFO: Injected into process with pid 6964 and name u'Unicorn-48656.exe'
2025-06-24 21:39:21,342 [analyzer] INFO: Injected into process with pid 7084 and name u'Unicorn-13471.exe'
2025-06-24 21:39:21,342 [analyzer] INFO: Injected into process with pid 6348 and name u'Unicorn-51744.exe'
2025-06-24 21:39:21,342 [analyzer] INFO: Injected into process with pid 6272 and name u'Unicorn-41678.exe'
2025-06-24 21:39:21,342 [analyzer] INFO: Injected into process with pid 6224 and name u'Unicorn-59942.exe'
2025-06-24 21:39:21,375 [analyzer] DEBUG: Loaded monitor into process with pid 6896
2025-06-24 21:39:21,390 [analyzer] INFO: Injected into process with pid 6188 and name u'Unicorn-33519.exe'
2025-06-24 21:39:21,390 [analyzer] INFO: Injected into process with pid 6192 and name u'Unicorn-62679.exe'
2025-06-24 21:39:21,437 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48895.exe
2025-06-24 21:39:21,515 [analyzer] DEBUG: Loaded monitor into process with pid 6996
2025-06-24 21:39:21,515 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10629.exe
2025-06-24 21:39:21,515 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10629.exe
2025-06-24 21:39:21,546 [analyzer] DEBUG: Loaded monitor into process with pid 7016
2025-06-24 21:39:21,562 [analyzer] DEBUG: Loaded monitor into process with pid 6980
2025-06-24 21:39:21,578 [analyzer] DEBUG: Loaded monitor into process with pid 7032
2025-06-24 21:39:21,592 [analyzer] DEBUG: Loaded monitor into process with pid 6964
2025-06-24 21:39:21,592 [analyzer] DEBUG: Loaded monitor into process with pid 7024
2025-06-24 21:39:21,608 [analyzer] DEBUG: Loaded monitor into process with pid 6972
2025-06-24 21:39:21,625 [analyzer] DEBUG: Loaded monitor into process with pid 7004
2025-06-24 21:39:21,625 [analyzer] DEBUG: Loaded monitor into process with pid 6988
2025-06-24 21:39:21,640 [analyzer] DEBUG: Loaded monitor into process with pid 6272
2025-06-24 21:39:21,655 [analyzer] DEBUG: Loaded monitor into process with pid 6224
2025-06-24 21:39:21,671 [analyzer] DEBUG: Loaded monitor into process with pid 7084
2025-06-24 21:39:21,671 [analyzer] DEBUG: Loaded monitor into process with pid 6348
2025-06-24 21:39:21,687 [analyzer] INFO: Injected into process with pid 6868 and name u'Unicorn-14581.exe'
2025-06-24 21:39:21,703 [analyzer] INFO: Injected into process with pid 372 and name u'Unicorn-846.exe'
2025-06-24 21:39:21,717 [analyzer] DEBUG: Loaded monitor into process with pid 6192
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10415.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10415.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4550.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10415.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4550.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4550.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4550.exe
2025-06-24 21:39:21,733 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4550.exe
2025-06-24 21:39:21,750 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50752.exe
2025-06-24 21:39:21,750 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50752.exe
2025-06-24 21:39:21,750 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50752.exe
2025-06-24 21:39:21,750 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50752.exe
2025-06-24 21:39:21,765 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56352.exe
2025-06-24 21:39:21,765 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50752.exe
2025-06-24 21:39:21,765 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56352.exe
2025-06-24 21:39:21,765 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1750.exe
2025-06-24 21:39:21,765 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46286.exe
2025-06-24 21:39:21,780 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1750.exe
2025-06-24 21:39:21,780 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1750.exe
2025-06-24 21:39:21,812 [analyzer] DEBUG: Loaded monitor into process with pid 6188
2025-06-24 21:39:21,828 [analyzer] INFO: Injected into process with pid 2024 and name u'Unicorn-60783.exe'
2025-06-24 21:39:22,937 [analyzer] DEBUG: Loaded monitor into process with pid 6868
2025-06-24 21:39:22,953 [analyzer] DEBUG: Loaded monitor into process with pid 372
2025-06-24 21:39:22,983 [analyzer] DEBUG: Loaded monitor into process with pid 2024
2025-06-24 21:39:23,092 [analyzer] INFO: Injected into process with pid 7120 and name u'Unicorn-48895.exe'
2025-06-24 21:39:23,155 [analyzer] INFO: Injected into process with pid 6360 and name u'Unicorn-10629.exe'
2025-06-24 21:39:23,203 [analyzer] INFO: Injected into process with pid 1176 and name u'Unicorn-50752.exe'
2025-06-24 21:39:23,203 [analyzer] INFO: Injected into process with pid 1280 and name u'Unicorn-10415.exe'
2025-06-24 21:39:23,217 [analyzer] INFO: Injected into process with pid 6708 and name u'Unicorn-4550.exe'
2025-06-24 21:39:23,265 [analyzer] INFO: Injected into process with pid 2864 and name u'Unicorn-56352.exe'
2025-06-24 21:39:23,265 [analyzer] INFO: Injected into process with pid 6756 and name u'Unicorn-1750.exe'
2025-06-24 21:39:23,265 [analyzer] INFO: Injected into process with pid 2148 and name u'Unicorn-46286.exe'
2025-06-24 21:39:23,342 [analyzer] DEBUG: Loaded monitor into process with pid 7120
2025-06-24 21:39:23,375 [analyzer] DEBUG: Loaded monitor into process with pid 6360
2025-06-24 21:39:23,405 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9830.exe
2025-06-24 21:39:23,421 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34832.exe
2025-06-24 21:39:23,421 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26166.exe
2025-06-24 21:39:23,437 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4478.exe
2025-06-24 21:39:23,530 [analyzer] DEBUG: Loaded monitor into process with pid 1280
2025-06-24 21:39:23,530 [analyzer] DEBUG: Loaded monitor into process with pid 6708
2025-06-24 21:39:23,578 [analyzer] DEBUG: Loaded monitor into process with pid 1176
2025-06-24 21:39:23,625 [analyzer] DEBUG: Loaded monitor into process with pid 2148
2025-06-24 21:39:23,625 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42646.exe
2025-06-24 21:39:23,671 [analyzer] DEBUG: Loaded monitor into process with pid 6756
2025-06-24 21:39:23,750 [analyzer] DEBUG: Loaded monitor into process with pid 2864
2025-06-24 21:39:23,953 [analyzer] INFO: Injected into process with pid 6944 and name u'Unicorn-9830.exe'
2025-06-24 21:39:23,953 [analyzer] INFO: Injected into process with pid 1384 and name u'Unicorn-26166.exe'
2025-06-24 21:39:23,953 [analyzer] INFO: Injected into process with pid 6876 and name u'Unicorn-4478.exe'
2025-06-24 21:39:23,953 [analyzer] INFO: Injected into process with pid 348 and name u'Unicorn-34832.exe'
2025-06-24 21:39:24,125 [analyzer] INFO: Injected into process with pid 6872 and name u'Unicorn-42646.exe'
2025-06-24 21:39:24,203 [analyzer] DEBUG: Loaded monitor into process with pid 348
2025-06-24 21:39:24,233 [analyzer] DEBUG: Loaded monitor into process with pid 1384
2025-06-24 21:39:24,265 [analyzer] DEBUG: Loaded monitor into process with pid 6876
2025-06-24 21:39:24,265 [analyzer] DEBUG: Loaded monitor into process with pid 6944
2025-06-24 21:39:24,312 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39071.exe
2025-06-24 21:39:24,375 [analyzer] DEBUG: Loaded monitor into process with pid 6872
2025-06-24 21:39:24,687 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35391.exe
2025-06-24 21:39:24,703 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-49574.exe
2025-06-24 21:39:24,703 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47304.exe
2025-06-24 21:39:24,703 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46774.exe
2025-06-24 21:39:24,703 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55439.exe
2025-06-24 21:39:24,733 [analyzer] INFO: Injected into process with pid 7228 and name u'Unicorn-39071.exe'
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38527.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38527.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13326.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13326.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30392.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38527.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30392.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30392.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30392.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38527.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32661.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38527.exe
2025-06-24 21:39:24,905 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29861.exe
2025-06-24 21:39:24,967 [analyzer] DEBUG: Loaded monitor into process with pid 7228
2025-06-24 21:39:25,578 [analyzer] INFO: Injected into process with pid 7264 and name u'Unicorn-35391.exe'
2025-06-24 21:39:25,687 [analyzer] INFO: Injected into process with pid 7280 and name u'Unicorn-49574.exe'
2025-06-24 21:39:25,687 [analyzer] INFO: Injected into process with pid 7296 and name u'Unicorn-47304.exe'
2025-06-24 21:39:25,687 [analyzer] INFO: Injected into process with pid 7288 and name u'Unicorn-46774.exe'
2025-06-24 21:39:25,703 [analyzer] INFO: Injected into process with pid 7304 and name u'Unicorn-55439.exe'
2025-06-24 21:39:25,858 [analyzer] INFO: Injected into process with pid 7416 and name u'Unicorn-32661.exe'
2025-06-24 21:39:25,858 [analyzer] INFO: Injected into process with pid 7400 and name u'Unicorn-13326.exe'
2025-06-24 21:39:25,858 [analyzer] INFO: Injected into process with pid 7424 and name u'Unicorn-38527.exe'
2025-06-24 21:39:25,858 [analyzer] INFO: Injected into process with pid 7408 and name u'Unicorn-30392.exe'
2025-06-24 21:39:25,875 [analyzer] INFO: Injected into process with pid 7432 and name u'Unicorn-29861.exe'
2025-06-24 21:39:25,890 [analyzer] DEBUG: Loaded monitor into process with pid 7264
2025-06-24 21:39:25,953 [analyzer] DEBUG: Loaded monitor into process with pid 7288
2025-06-24 21:39:26,015 [analyzer] DEBUG: Loaded monitor into process with pid 7280
2025-06-24 21:39:26,078 [analyzer] DEBUG: Loaded monitor into process with pid 7296
2025-06-24 21:39:26,092 [analyzer] DEBUG: Loaded monitor into process with pid 7304
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13061.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13061.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57597.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57597.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57597.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13061.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13591.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62063.exe
2025-06-24 21:39:31,358 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13061.exe
2025-06-24 21:39:31,453 [analyzer] DEBUG: Loaded monitor into process with pid 7416
2025-06-24 21:39:31,515 [analyzer] DEBUG: Loaded monitor into process with pid 7400
2025-06-24 21:39:31,530 [analyzer] DEBUG: Loaded monitor into process with pid 7424
2025-06-24 21:39:31,546 [analyzer] DEBUG: Loaded monitor into process with pid 7408
2025-06-24 21:39:31,592 [analyzer] DEBUG: Loaded monitor into process with pid 7432
2025-06-24 21:39:31,750 [analyzer] INFO: Injected into process with pid 7796 and name u'Unicorn-13591.exe'
2025-06-24 21:39:31,750 [analyzer] INFO: Injected into process with pid 7808 and name u'Unicorn-62063.exe'
2025-06-24 21:39:31,765 [analyzer] INFO: Injected into process with pid 7816 and name u'Unicorn-13061.exe'
2025-06-24 21:39:31,765 [analyzer] INFO: Injected into process with pid 7788 and name u'Unicorn-57597.exe'
2025-06-24 21:39:38,625 [analyzer] DEBUG: Loaded monitor into process with pid 7816
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58745.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58745.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41679.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58745.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58745.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31879.exe
2025-06-24 21:39:38,687 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58745.exe
2025-06-24 21:39:38,765 [analyzer] DEBUG: Loaded monitor into process with pid 7788
2025-06-24 21:39:38,812 [analyzer] DEBUG: Loaded monitor into process with pid 7796
2025-06-24 21:39:38,890 [analyzer] DEBUG: Loaded monitor into process with pid 7808
2025-06-24 21:39:52,171 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19771.exe
2025-06-24 21:39:52,171 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40772.exe
2025-06-24 21:39:52,421 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7907.exe
2025-06-24 21:39:52,421 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56909.exe
2025-06-24 21:39:52,437 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59179.exe
2025-06-24 21:39:52,515 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47846.exe
2025-06-24 21:39:52,687 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48844.exe
2025-06-24 21:39:52,796 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57890.exe
2025-06-24 21:39:52,796 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-17553.exe
2025-06-24 21:39:52,796 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-40989.exe
2025-06-24 21:39:52,812 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16325.exe
2025-06-24 21:39:52,828 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24461.exe
2025-06-24 21:39:52,828 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24461.exe
2025-06-24 21:39:52,828 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64797.exe
2025-06-24 21:39:52,828 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24461.exe
2025-06-24 21:39:52,875 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54996.exe
2025-06-24 21:39:52,921 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48468.exe
2025-06-24 21:39:52,937 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-8504.exe
2025-06-24 21:39:52,937 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51268.exe
2025-06-24 21:39:53,030 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50884.exe
2025-06-24 21:39:53,078 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43227.exe
2025-06-24 21:39:53,125 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24436.exe
2025-06-24 21:39:53,140 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51302.exe
2025-06-24 21:39:53,140 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29771.exe
2025-06-24 21:39:53,171 [analyzer] INFO: Injected into process with pid 8000 and name u'Unicorn-41679.exe'
2025-06-24 21:39:53,187 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27675.exe
2025-06-24 21:39:53,187 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6144.exe
2025-06-24 21:39:53,203 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-17708.exe
2025-06-24 21:39:53,203 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13243.exe
2025-06-24 21:39:53,217 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34774.exe
2025-06-24 21:39:53,217 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34243.exe
2025-06-24 21:39:53,233 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60347.exe
2025-06-24 21:39:53,312 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1180.exe
2025-06-24 21:39:53,312 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-18245.exe
2025-06-24 21:39:53,312 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-17715.exe
2025-06-24 21:39:53,328 [analyzer] INFO: Injected into process with pid 8020 and name u'Unicorn-58745.exe'
2025-06-24 21:39:53,328 [analyzer] INFO: Injected into process with pid 8040 and name u'Unicorn-41679.exe'
2025-06-24 21:39:53,358 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33852.exe
2025-06-24 21:39:53,375 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26753.exe
2025-06-24 21:39:53,390 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53188.exe
2025-06-24 21:39:53,405 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53188.exe
2025-06-24 21:39:53,405 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59053.exe
2025-06-24 21:39:53,421 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43289.exe
2025-06-24 21:39:53,421 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59426.exe
2025-06-24 21:39:53,453 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13224.exe
2025-06-24 21:39:53,437 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19089.exe
2025-06-24 21:39:53,453 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35426.exe
2025-06-24 21:39:53,453 [analyzer] INFO: Injected into process with pid 8012 and name u'Unicorn-31879.exe'
2025-06-24 21:39:53,453 [analyzer] INFO: Injected into process with pid 8048 and name u'Unicorn-41679.exe'
2025-06-24 21:39:53,467 [analyzer] INFO: Injected into process with pid 8056 and name u'Unicorn-31879.exe'
2025-06-24 21:39:53,750 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11580.exe
2025-06-24 21:39:53,796 [analyzer] INFO: Injected into process with pid 6512 and name u'Unicorn-40772.exe'
2025-06-24 21:39:53,796 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51533.exe
2025-06-24 21:39:53,796 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3061.exe
2025-06-24 21:39:53,796 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41732.exe
2025-06-24 21:39:53,812 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57133.exe
2025-06-24 21:39:53,828 [analyzer] DEBUG: Loaded monitor into process with pid 8000
2025-06-24 21:39:53,842 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47067.exe
2025-06-24 21:39:53,890 [analyzer] INFO: Injected into process with pid 8188 and name u'Unicorn-19771.exe'
2025-06-24 21:39:53,937 [analyzer] INFO: Injected into process with pid 7256 and name u'Unicorn-47846.exe'
2025-06-24 21:39:54,046 [analyzer] DEBUG: Loaded monitor into process with pid 8020
2025-06-24 21:39:54,062 [analyzer] INFO: Injected into process with pid 2204 and name u'Unicorn-7907.exe'
2025-06-24 21:39:54,078 [analyzer] INFO: Injected into process with pid 7240 and name u'Unicorn-59179.exe'
2025-06-24 21:39:54,078 [analyzer] INFO: Injected into process with pid 7172 and name u'Unicorn-56909.exe'
2025-06-24 21:39:54,108 [analyzer] INFO: Injected into process with pid 7532 and name u'Unicorn-48844.exe'
2025-06-24 21:39:54,171 [analyzer] INFO: Injected into process with pid 7576 and name u'Unicorn-54996.exe'
2025-06-24 21:39:54,171 [analyzer] INFO: Injected into process with pid 7516 and name u'Unicorn-40989.exe'
2025-06-24 21:39:54,187 [analyzer] INFO: Injected into process with pid 7536 and name u'Unicorn-57890.exe'
2025-06-24 21:39:54,217 [analyzer] INFO: Injected into process with pid 7632 and name u'Unicorn-16325.exe'
2025-06-24 21:39:54,217 [analyzer] INFO: Injected into process with pid 7540 and name u'Unicorn-17553.exe'
2025-06-24 21:39:54,250 [analyzer] INFO: Injected into process with pid 7644 and name u'Unicorn-64797.exe'
2025-06-24 21:39:54,280 [analyzer] INFO: Injected into process with pid 7600 and name u'Unicorn-24461.exe'
2025-06-24 21:39:54,280 [analyzer] INFO: Injected into process with pid 7608 and name u'Unicorn-24461.exe'
2025-06-24 21:39:54,296 [analyzer] INFO: Injected into process with pid 7880 and name u'Unicorn-48468.exe'
2025-06-24 21:39:54,296 [analyzer] INFO: Injected into process with pid 7868 and name u'Unicorn-8504.exe'
2025-06-24 21:39:54,312 [analyzer] INFO: Injected into process with pid 7908 and name u'Unicorn-51268.exe'
2025-06-24 21:39:54,312 [analyzer] DEBUG: Loaded monitor into process with pid 8040
2025-06-24 21:39:54,342 [analyzer] INFO: Injected into process with pid 8080 and name u'Unicorn-50884.exe'
2025-06-24 21:39:54,358 [analyzer] DEBUG: Loaded monitor into process with pid 8012
2025-06-24 21:39:54,390 [analyzer] INFO: Injected into process with pid 8124 and name u'Unicorn-43227.exe'
2025-06-24 21:39:54,421 [analyzer] INFO: Injected into process with pid 6748 and name u'Unicorn-43227.exe'
2025-06-24 21:39:54,437 [analyzer] DEBUG: Loaded monitor into process with pid 8056
2025-06-24 21:39:54,453 [analyzer] INFO: Injected into process with pid 8108 and name u'Unicorn-24436.exe'
2025-06-24 21:39:54,467 [analyzer] INFO: Injected into process with pid 8132 and name u'Unicorn-51302.exe'
2025-06-24 21:39:54,483 [analyzer] DEBUG: Loaded monitor into process with pid 6512
2025-06-24 21:39:54,515 [analyzer] INFO: Injected into process with pid 8216 and name u'Unicorn-27675.exe'
2025-06-24 21:39:54,546 [analyzer] DEBUG: Loaded monitor into process with pid 8048
2025-06-24 21:39:54,546 [analyzer] INFO: Injected into process with pid 8148 and name u'Unicorn-29771.exe'
2025-06-24 21:39:54,562 [analyzer] INFO: Injected into process with pid 8224 and name u'Unicorn-6144.exe'
2025-06-24 21:39:54,562 [analyzer] DEBUG: Loaded monitor into process with pid 8188
2025-06-24 21:39:54,592 [analyzer] DEBUG: Loaded monitor into process with pid 7256
2025-06-24 21:39:54,608 [analyzer] INFO: Injected into process with pid 8240 and name u'Unicorn-17708.exe'
2025-06-24 21:39:54,640 [analyzer] DEBUG: Loaded monitor into process with pid 2204
2025-06-24 21:39:54,640 [analyzer] INFO: Injected into process with pid 8232 and name u'Unicorn-17708.exe'
2025-06-24 21:39:54,671 [analyzer] INFO: Injected into process with pid 8260 and name u'Unicorn-34774.exe'
2025-06-24 21:39:54,671 [analyzer] INFO: Injected into process with pid 8248 and name u'Unicorn-13243.exe'
2025-06-24 21:39:54,687 [analyzer] INFO: Injected into process with pid 8364 and name u'Unicorn-17715.exe'
2025-06-24 21:39:54,703 [analyzer] INFO: Injected into process with pid 8340 and name u'Unicorn-18245.exe'
2025-06-24 21:39:54,717 [analyzer] DEBUG: Loaded monitor into process with pid 7172
2025-06-24 21:39:54,750 [analyzer] INFO: Injected into process with pid 8268 and name u'Unicorn-34243.exe'
2025-06-24 21:39:54,750 [analyzer] INFO: Injected into process with pid 8308 and name u'Unicorn-60347.exe'
2025-06-24 21:39:54,765 [analyzer] DEBUG: Loaded monitor into process with pid 7536
2025-06-24 21:39:54,780 [analyzer] DEBUG: Loaded monitor into process with pid 7516
2025-06-24 21:39:54,780 [analyzer] INFO: Injected into process with pid 8332 and name u'Unicorn-1180.exe'
2025-06-24 21:39:54,796 [analyzer] DEBUG: Loaded monitor into process with pid 7644
2025-06-24 21:39:54,796 [analyzer] INFO: Injected into process with pid 8540 and name u'Unicorn-59053.exe'
2025-06-24 21:39:54,796 [analyzer] DEBUG: Loaded monitor into process with pid 7240
2025-06-24 21:39:54,828 [analyzer] INFO: Injected into process with pid 8400 and name u'Unicorn-33852.exe'
2025-06-24 21:39:54,842 [analyzer] DEBUG: Loaded monitor into process with pid 7532
2025-06-24 21:39:54,842 [analyzer] INFO: Injected into process with pid 8372 and name u'Unicorn-17715.exe'
2025-06-24 21:39:54,858 [analyzer] DEBUG: Loaded monitor into process with pid 7540
2025-06-24 21:39:54,858 [analyzer] INFO: Injected into process with pid 8408 and name u'Unicorn-26753.exe'
2025-06-24 21:39:54,875 [analyzer] DEBUG: Loaded monitor into process with pid 7608
2025-06-24 21:39:54,875 [analyzer] DEBUG: Loaded monitor into process with pid 7632
2025-06-24 21:39:54,890 [analyzer] DEBUG: Loaded monitor into process with pid 7600
2025-06-24 21:39:54,890 [analyzer] INFO: Injected into process with pid 8488 and name u'Unicorn-53188.exe'
2025-06-24 21:39:54,890 [analyzer] INFO: Injected into process with pid 8580 and name u'Unicorn-43289.exe'
2025-06-24 21:39:54,905 [analyzer] DEBUG: Loaded monitor into process with pid 7880
2025-06-24 21:39:54,905 [analyzer] INFO: Injected into process with pid 8760 and name u'Unicorn-35426.exe'
2025-06-24 21:39:54,905 [analyzer] INFO: Injected into process with pid 8672 and name u'Unicorn-59426.exe'
2025-06-24 21:39:54,921 [analyzer] DEBUG: Loaded monitor into process with pid 7576
2025-06-24 21:39:54,937 [analyzer] INFO: Injected into process with pid 8688 and name u'Unicorn-13224.exe'
2025-06-24 21:39:54,953 [analyzer] DEBUG: Loaded monitor into process with pid 7868
2025-06-24 21:39:54,967 [analyzer] INFO: Injected into process with pid 8844 and name u'Unicorn-11580.exe'
2025-06-24 21:39:54,967 [analyzer] INFO: Injected into process with pid 8736 and name u'Unicorn-19089.exe'
2025-06-24 21:39:54,983 [analyzer] DEBUG: Loaded monitor into process with pid 8080
2025-06-24 21:39:55,000 [analyzer] DEBUG: Loaded monitor into process with pid 8124
2025-06-24 21:39:55,015 [analyzer] DEBUG: Loaded monitor into process with pid 8108
2025-06-24 21:39:55,015 [analyzer] INFO: Injected into process with pid 8932 and name u'Unicorn-51533.exe'
2025-06-24 21:39:55,078 [analyzer] INFO: Injected into process with pid 8956 and name u'Unicorn-3061.exe'
2025-06-24 21:39:55,078 [analyzer] DEBUG: Loaded monitor into process with pid 8148
2025-06-24 21:39:55,078 [analyzer] DEBUG: Loaded monitor into process with pid 8216
2025-06-24 21:39:55,078 [analyzer] DEBUG: Loaded monitor into process with pid 7908
2025-06-24 21:39:55,092 [analyzer] DEBUG: Loaded monitor into process with pid 6748
2025-06-24 21:39:55,078 [analyzer] INFO: Injected into process with pid 9024 and name u'Unicorn-57133.exe'
2025-06-24 21:39:55,092 [analyzer] DEBUG: Loaded monitor into process with pid 8232
2025-06-24 21:39:55,108 [analyzer] INFO: Injected into process with pid 8976 and name u'Unicorn-41732.exe'
2025-06-24 21:39:55,187 [analyzer] INFO: Injected into process with pid 9108 and name u'Unicorn-47067.exe'
2025-06-24 21:39:55,187 [analyzer] DEBUG: Loaded monitor into process with pid 8260
2025-06-24 21:39:55,187 [analyzer] DEBUG: Loaded monitor into process with pid 8340
2025-06-24 21:39:55,250 [analyzer] DEBUG: Loaded monitor into process with pid 8332
2025-06-24 21:39:55,280 [analyzer] DEBUG: Loaded monitor into process with pid 8240
2025-06-24 21:39:55,296 [analyzer] DEBUG: Loaded monitor into process with pid 8224
2025-06-24 21:39:55,312 [analyzer] DEBUG: Loaded monitor into process with pid 8132
2025-06-24 21:39:55,328 [analyzer] DEBUG: Loaded monitor into process with pid 8308
2025-06-24 21:39:55,342 [analyzer] DEBUG: Loaded monitor into process with pid 8672
2025-06-24 21:39:55,358 [analyzer] DEBUG: Loaded monitor into process with pid 8248
2025-06-24 21:39:55,358 [analyzer] DEBUG: Loaded monitor into process with pid 8372
2025-06-24 21:39:55,375 [analyzer] DEBUG: Loaded monitor into process with pid 8736
2025-06-24 21:39:55,375 [analyzer] DEBUG: Loaded monitor into process with pid 8268
2025-06-24 21:39:55,390 [analyzer] DEBUG: Loaded monitor into process with pid 8760
2025-06-24 21:39:55,405 [analyzer] DEBUG: Loaded monitor into process with pid 8400
2025-06-24 21:39:55,421 [analyzer] DEBUG: Loaded monitor into process with pid 8844
2025-06-24 21:39:55,437 [analyzer] DEBUG: Loaded monitor into process with pid 8956
2025-06-24 21:39:55,467 [analyzer] DEBUG: Loaded monitor into process with pid 8408
2025-06-24 21:39:55,467 [analyzer] DEBUG: Loaded monitor into process with pid 8932
2025-06-24 21:39:55,483 [analyzer] DEBUG: Loaded monitor into process with pid 8488
2025-06-24 21:39:55,500 [analyzer] DEBUG: Loaded monitor into process with pid 8976
2025-06-24 21:39:55,515 [analyzer] DEBUG: Loaded monitor into process with pid 8580
2025-06-24 21:39:55,530 [analyzer] DEBUG: Loaded monitor into process with pid 9108
2025-06-24 21:39:55,546 [analyzer] DEBUG: Loaded monitor into process with pid 8540
2025-06-24 21:39:55,546 [analyzer] DEBUG: Loaded monitor into process with pid 9024
2025-06-24 21:39:55,592 [analyzer] DEBUG: Loaded monitor into process with pid 8688
2025-06-24 21:39:55,625 [analyzer] DEBUG: Loaded monitor into process with pid 8364
2025-06-24 21:39:56,046 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2739.exe
2025-06-24 21:39:56,453 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7924.exe
2025-06-24 21:39:56,592 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5649.exe
2025-06-24 21:39:56,671 [analyzer] INFO: Injected into process with pid 2096 and name u'Unicorn-2739.exe'
2025-06-24 21:39:56,983 [analyzer] DEBUG: Loaded monitor into process with pid 2096
2025-06-24 21:39:57,015 [analyzer] INFO: Injected into process with pid 9140 and name u'Unicorn-7924.exe'
2025-06-24 21:39:57,092 [analyzer] INFO: Injected into process with pid 7392 and name u'Unicorn-5649.exe'
2025-06-24 21:39:57,265 [analyzer] DEBUG: Loaded monitor into process with pid 9140
2025-06-24 21:39:57,328 [analyzer] DEBUG: Loaded monitor into process with pid 7392
2025-06-24 21:40:12,437 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51501.exe
2025-06-24 21:40:12,437 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3029.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47035.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41700.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41700.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47035.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2499.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11164.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-47035.exe
2025-06-24 21:40:12,453 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3029.exe
2025-06-24 21:40:12,467 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41700.exe
2025-06-24 21:40:12,515 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45900.exe
2025-06-24 21:40:14,015 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4412.exe
2025-06-24 21:40:14,015 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63387.exe
2025-06-24 21:40:14,030 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7253.exe
2025-06-24 21:40:14,328 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12645.exe
2025-06-24 21:40:14,342 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20780.exe
2025-06-24 21:40:14,375 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21153.exe
2025-06-24 21:40:14,437 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23595.exe
2025-06-24 21:40:14,578 [analyzer] INFO: Injected into process with pid 9104 and name u'Unicorn-41700.exe'
2025-06-24 21:40:14,592 [analyzer] INFO: Injected into process with pid 7892 and name u'Unicorn-41700.exe'
2025-06-24 21:40:14,655 [analyzer] INFO: Injected into process with pid 8556 and name u'Unicorn-11164.exe'
2025-06-24 21:40:14,655 [analyzer] INFO: Injected into process with pid 9072 and name u'Unicorn-41700.exe'
2025-06-24 21:40:14,671 [analyzer] INFO: Injected into process with pid 8116 and name u'Unicorn-2499.exe'
2025-06-24 21:40:14,671 [analyzer] INFO: Injected into process with pid 2540 and name u'Unicorn-2499.exe'
2025-06-24 21:40:14,687 [analyzer] INFO: Injected into process with pid 7476 and name u'Unicorn-41700.exe'
2025-06-24 21:40:14,703 [analyzer] INFO: Injected into process with pid 9160 and name u'Unicorn-41700.exe'
2025-06-24 21:40:14,717 [analyzer] INFO: Injected into process with pid 7936 and name u'Unicorn-45900.exe'
2025-06-24 21:40:14,750 [analyzer] INFO: Injected into process with pid 8440 and name u'Unicorn-2499.exe'
2025-06-24 21:40:14,750 [analyzer] INFO: Injected into process with pid 804 and name u'Unicorn-45900.exe'
2025-06-24 21:40:14,750 [analyzer] INFO: Injected into process with pid 9304 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,750 [analyzer] INFO: Injected into process with pid 9016 and name u'Unicorn-11164.exe'
2025-06-24 21:40:14,812 [analyzer] INFO: Injected into process with pid 9328 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,828 [analyzer] INFO: Injected into process with pid 9312 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,828 [analyzer] INFO: Injected into process with pid 9320 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,828 [analyzer] INFO: Injected into process with pid 8072 and name u'Unicorn-2499.exe'
2025-06-24 21:40:14,828 [analyzer] INFO: Injected into process with pid 9368 and name u'Unicorn-47035.exe'
2025-06-24 21:40:14,937 [analyzer] DEBUG: Loaded monitor into process with pid 7892
2025-06-24 21:40:14,953 [analyzer] DEBUG: Loaded monitor into process with pid 9072
2025-06-24 21:40:14,967 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55561.exe
2025-06-24 21:40:14,983 [analyzer] INFO: Injected into process with pid 9336 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,983 [analyzer] INFO: Injected into process with pid 9352 and name u'Unicorn-3029.exe'
2025-06-24 21:40:14,983 [analyzer] INFO: Injected into process with pid 9248 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,015 [analyzer] DEBUG: Loaded monitor into process with pid 8556
2025-06-24 21:40:15,030 [analyzer] INFO: Injected into process with pid 3032 and name u'Unicorn-2499.exe'
2025-06-24 21:40:15,062 [analyzer] INFO: Injected into process with pid 9264 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,092 [analyzer] INFO: Injected into process with pid 9288 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,092 [analyzer] INFO: Injected into process with pid 9376 and name u'Unicorn-47035.exe'
2025-06-24 21:40:15,108 [analyzer] DEBUG: Loaded monitor into process with pid 8116
2025-06-24 21:40:15,140 [analyzer] INFO: Injected into process with pid 9344 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,140 [analyzer] DEBUG: Loaded monitor into process with pid 9104
2025-06-24 21:40:15,155 [analyzer] DEBUG: Loaded monitor into process with pid 2540
2025-06-24 21:40:15,155 [analyzer] INFO: Injected into process with pid 9296 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,187 [analyzer] DEBUG: Loaded monitor into process with pid 7476
2025-06-24 21:40:15,203 [analyzer] INFO: Injected into process with pid 9384 and name u'Unicorn-47035.exe'
2025-06-24 21:40:15,203 [analyzer] DEBUG: Loaded monitor into process with pid 9160
2025-06-24 21:40:15,203 [analyzer] INFO: Injected into process with pid 9360 and name u'Unicorn-47035.exe'
2025-06-24 21:40:15,203 [analyzer] INFO: Injected into process with pid 9280 and name u'Unicorn-47035.exe'
2025-06-24 21:40:15,233 [analyzer] DEBUG: Loaded monitor into process with pid 8440
2025-06-24 21:40:15,233 [analyzer] INFO: Injected into process with pid 9256 and name u'Unicorn-51501.exe'
2025-06-24 21:40:15,233 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53008.exe
2025-06-24 21:40:15,250 [analyzer] DEBUG: Loaded monitor into process with pid 8072
2025-06-24 21:40:15,265 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11272.exe
2025-06-24 21:40:15,265 [analyzer] DEBUG: Loaded monitor into process with pid 9320
2025-06-24 21:40:15,280 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-15571.exe
2025-06-24 21:40:15,296 [analyzer] DEBUG: Loaded monitor into process with pid 9304
2025-06-24 21:40:15,342 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24237.exe
2025-06-24 21:40:15,342 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16101.exe
2025-06-24 21:40:15,358 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35345.exe
2025-06-24 21:40:15,358 [analyzer] INFO: Injected into process with pid 9272 and name u'Unicorn-3029.exe'
2025-06-24 21:40:15,358 [analyzer] INFO: Injected into process with pid 10020 and name u'Unicorn-12645.exe'
2025-06-24 21:40:15,358 [analyzer] INFO: Injected into process with pid 10044 and name u'Unicorn-21153.exe'
2025-06-24 21:40:15,358 [analyzer] INFO: Injected into process with pid 9868 and name u'Unicorn-4412.exe'
2025-06-24 21:40:15,358 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31145.exe
2025-06-24 21:40:15,358 [analyzer] INFO: Injected into process with pid 9888 and name u'Unicorn-7253.exe'
2025-06-24 21:40:15,375 [analyzer] INFO: Injected into process with pid 9900 and name u'Unicorn-63387.exe'
2025-06-24 21:40:15,375 [analyzer] INFO: Injected into process with pid 10108 and name u'Unicorn-23595.exe'
2025-06-24 21:40:15,390 [analyzer] DEBUG: Loaded monitor into process with pid 9336
2025-06-24 21:40:15,390 [analyzer] DEBUG: Loaded monitor into process with pid 804
2025-06-24 21:40:15,405 [analyzer] DEBUG: Loaded monitor into process with pid 9368
2025-06-24 21:40:15,405 [analyzer] DEBUG: Loaded monitor into process with pid 9312
2025-06-24 21:40:15,405 [analyzer] DEBUG: Loaded monitor into process with pid 9016
2025-06-24 21:40:15,515 [analyzer] INFO: Injected into process with pid 10028 and name u'Unicorn-20780.exe'
2025-06-24 21:40:15,500 [analyzer] DEBUG: Loaded monitor into process with pid 9352
2025-06-24 21:40:15,625 [analyzer] DEBUG: Loaded monitor into process with pid 9248
2025-06-24 21:40:15,530 [analyzer] DEBUG: Loaded monitor into process with pid 7936
2025-06-24 21:40:15,655 [analyzer] DEBUG: Loaded monitor into process with pid 9264
2025-06-24 21:40:15,671 [analyzer] DEBUG: Loaded monitor into process with pid 3032
2025-06-24 21:40:15,687 [analyzer] DEBUG: Loaded monitor into process with pid 9376
2025-06-24 21:40:15,703 [analyzer] DEBUG: Loaded monitor into process with pid 9344
2025-06-24 21:40:15,733 [analyzer] DEBUG: Loaded monitor into process with pid 9280
2025-06-24 21:40:15,733 [analyzer] DEBUG: Loaded monitor into process with pid 9288
2025-06-24 21:40:15,750 [analyzer] DEBUG: Loaded monitor into process with pid 9296
2025-06-24 21:40:15,780 [analyzer] DEBUG: Loaded monitor into process with pid 9360
2025-06-24 21:40:15,812 [analyzer] DEBUG: Loaded monitor into process with pid 9328
2025-06-24 21:40:15,828 [analyzer] DEBUG: Loaded monitor into process with pid 9384
2025-06-24 21:40:15,905 [analyzer] DEBUG: Loaded monitor into process with pid 9256
2025-06-24 21:40:15,905 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-10732.exe
2025-06-24 21:40:15,905 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11867.exe
2025-06-24 21:40:15,921 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48533.exe
2025-06-24 21:40:15,921 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6532.exe
2025-06-24 21:40:16,000 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52641.exe
2025-06-24 21:40:16,015 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9240.exe
2025-06-24 21:40:16,015 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58242.exe
2025-06-24 21:40:16,015 [analyzer] DEBUG: Loaded monitor into process with pid 9272
2025-06-24 21:40:16,030 [analyzer] DEBUG: Loaded monitor into process with pid 10020
2025-06-24 21:40:16,187 [analyzer] DEBUG: Loaded monitor into process with pid 10044
2025-06-24 21:40:16,250 [analyzer] DEBUG: Loaded monitor into process with pid 10028
2025-06-24 21:40:16,250 [analyzer] DEBUG: Loaded monitor into process with pid 9888
2025-06-24 21:40:16,312 [analyzer] DEBUG: Loaded monitor into process with pid 10108
2025-06-24 21:40:16,312 [analyzer] INFO: Injected into process with pid 9748 and name u'Unicorn-55561.exe'
2025-06-24 21:40:16,358 [analyzer] DEBUG: Loaded monitor into process with pid 9868
2025-06-24 21:40:16,390 [analyzer] DEBUG: Loaded monitor into process with pid 9900
2025-06-24 21:40:16,500 [analyzer] INFO: Injected into process with pid 9924 and name u'Unicorn-15571.exe'
2025-06-24 21:40:16,500 [analyzer] INFO: Injected into process with pid 10152 and name u'Unicorn-15571.exe'
2025-06-24 21:40:16,530 [analyzer] INFO: Injected into process with pid 9824 and name u'Unicorn-11272.exe'
2025-06-24 21:40:16,592 [analyzer] INFO: Injected into process with pid 10188 and name u'Unicorn-16101.exe'
2025-06-24 21:40:16,592 [analyzer] INFO: Injected into process with pid 10080 and name u'Unicorn-53008.exe'
2025-06-24 21:40:16,592 [analyzer] INFO: Injected into process with pid 9400 and name u'Unicorn-35345.exe'
2025-06-24 21:40:16,625 [analyzer] DEBUG: Loaded monitor into process with pid 9748
2025-06-24 21:40:16,655 [analyzer] INFO: Injected into process with pid 9232 and name u'Unicorn-31145.exe'
2025-06-24 21:40:16,671 [analyzer] INFO: Injected into process with pid 10120 and name u'Unicorn-24237.exe'
2025-06-24 21:40:16,765 [analyzer] INFO: Injected into process with pid 9936 and name u'Unicorn-48533.exe'
2025-06-24 21:40:16,780 [analyzer] INFO: Injected into process with pid 9620 and name u'Unicorn-10732.exe'
2025-06-24 21:40:16,875 [analyzer] INFO: Injected into process with pid 10384 and name u'Unicorn-58242.exe'
2025-06-24 21:40:16,875 [analyzer] DEBUG: Loaded monitor into process with pid 10152
2025-06-24 21:40:16,875 [analyzer] INFO: Injected into process with pid 10332 and name u'Unicorn-52641.exe'
2025-06-24 21:40:16,875 [analyzer] INFO: Injected into process with pid 9876 and name u'Unicorn-6532.exe'
2025-06-24 21:40:16,890 [analyzer] INFO: Injected into process with pid 10340 and name u'Unicorn-9240.exe'
2025-06-24 21:40:16,905 [analyzer] INFO: Injected into process with pid 9716 and name u'Unicorn-10732.exe'
2025-06-24 21:40:16,905 [analyzer] INFO: Injected into process with pid 10252 and name u'Unicorn-11867.exe'
2025-06-24 21:40:16,905 [analyzer] INFO: Injected into process with pid 10260 and name u'Unicorn-11867.exe'
2025-06-24 21:40:16,905 [analyzer] INFO: Injected into process with pid 10244 and name u'Unicorn-6532.exe'
2025-06-24 21:40:16,967 [analyzer] INFO: Injected into process with pid 10268 and name u'Unicorn-11867.exe'
2025-06-24 21:40:16,967 [analyzer] INFO: Injected into process with pid 9840 and name u'Unicorn-48533.exe'
2025-06-24 21:40:17,000 [analyzer] DEBUG: Loaded monitor into process with pid 9924
2025-06-24 21:40:17,030 [analyzer] DEBUG: Loaded monitor into process with pid 10080
2025-06-24 21:40:17,046 [analyzer] DEBUG: Loaded monitor into process with pid 9824
2025-06-24 21:40:17,062 [analyzer] DEBUG: Loaded monitor into process with pid 9232
2025-06-24 21:40:17,078 [analyzer] DEBUG: Loaded monitor into process with pid 9400
2025-06-24 21:40:17,078 [analyzer] DEBUG: Loaded monitor into process with pid 10188
2025-06-24 21:40:17,125 [analyzer] DEBUG: Loaded monitor into process with pid 9936
2025-06-24 21:40:17,140 [analyzer] DEBUG: Loaded monitor into process with pid 10120
2025-06-24 21:40:17,155 [analyzer] DEBUG: Loaded monitor into process with pid 9620
2025-06-24 21:40:17,233 [analyzer] DEBUG: Loaded monitor into process with pid 10332
2025-06-24 21:40:17,250 [analyzer] DEBUG: Loaded monitor into process with pid 10384
2025-06-24 21:40:17,265 [analyzer] DEBUG: Loaded monitor into process with pid 10244
2025-06-24 21:40:17,280 [analyzer] DEBUG: Loaded monitor into process with pid 10340
2025-06-24 21:40:17,312 [analyzer] DEBUG: Loaded monitor into process with pid 9876
2025-06-24 21:40:17,328 [analyzer] DEBUG: Loaded monitor into process with pid 10252
2025-06-24 21:40:17,342 [analyzer] DEBUG: Loaded monitor into process with pid 9840
2025-06-24 21:40:17,358 [analyzer] DEBUG: Loaded monitor into process with pid 10268
2025-06-24 21:40:17,375 [analyzer] DEBUG: Loaded monitor into process with pid 9716
2025-06-24 21:40:17,390 [analyzer] DEBUG: Loaded monitor into process with pid 10260
2025-06-24 21:40:18,515 [analyzer] INFO: Added new file to list with pid 4404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24614.exe
2025-06-24 21:40:19,015 [analyzer] INFO: Injected into process with pid 10972 and name u'Unicorn-24614.exe'
2025-06-24 21:40:19,250 [analyzer] DEBUG: Loaded monitor into process with pid 10972
2025-06-24 21:40:30,671 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29753.exe
2025-06-24 21:40:30,671 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39553.exe
2025-06-24 21:40:30,687 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35088.exe
2025-06-24 21:40:30,717 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56619.exe
2025-06-24 21:40:30,733 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33953.exe
2025-06-24 21:40:30,733 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33953.exe
2025-06-24 21:40:30,750 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56089.exe
2025-06-24 21:40:30,750 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56089.exe
2025-06-24 21:40:30,765 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56089.exe
2025-06-24 21:40:30,765 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6217.exe
2025-06-24 21:40:30,765 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6217.exe
2025-06-24 21:40:38,467 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45441.exe
2025-06-24 21:40:39,062 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56293.exe
2025-06-24 21:40:39,078 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-49293.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46964.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-664.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-14273.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39865.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7001.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45200.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28672.exe
2025-06-24 21:40:39,342 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11201.exe
2025-06-24 21:40:39,453 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35003.exe
2025-06-24 21:40:39,453 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,453 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,453 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6132.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6132.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39468.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6132.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33868.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35003.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6132.exe
2025-06-24 21:40:39,467 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33868.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33868.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33868.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56534.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35003.exe
2025-06-24 21:40:39,483 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35003.exe
2025-06-24 21:40:39,515 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
2025-06-24 21:40:39,546 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33868.exe
2025-06-24 21:40:39,546 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5105.exe
2025-06-24 21:40:39,546 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60576.exe
2025-06-24 21:40:39,546 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1004.exe
2025-06-24 21:40:39,562 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62341.exe
2025-06-24 21:40:39,562 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38805.exe
2025-06-24 21:40:39,562 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2139.exe
2025-06-24 21:40:39,578 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22940.exe
2025-06-24 21:40:39,578 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55141.exe
2025-06-24 21:40:39,578 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55141.exe
2025-06-24 21:40:39,578 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22940.exe
2025-06-24 21:40:39,592 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29284.exe
2025-06-24 21:40:39,592 [analyzer] INFO: Injected into process with pid 11056 and name u'Unicorn-33953.exe'
2025-06-24 21:40:39,592 [analyzer] INFO: Injected into process with pid 11040 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,608 [analyzer] INFO: Injected into process with pid 11088 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,608 [analyzer] INFO: Injected into process with pid 11080 and name u'Unicorn-56089.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11104 and name u'Unicorn-29753.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11064 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11096 and name u'Unicorn-35088.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11128 and name u'Unicorn-6217.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11120 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,625 [analyzer] INFO: Injected into process with pid 11136 and name u'Unicorn-6217.exe'
2025-06-24 21:40:39,655 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1809.exe
2025-06-24 21:40:39,717 [analyzer] INFO: Injected into process with pid 11072 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,750 [analyzer] INFO: Injected into process with pid 11112 and name u'Unicorn-56619.exe'
2025-06-24 21:40:39,750 [analyzer] INFO: Injected into process with pid 11048 and name u'Unicorn-39553.exe'
2025-06-24 21:40:39,780 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61362.exe
2025-06-24 21:40:40,233 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10736,10304,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:40:40,296 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10780,10628,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:40:40,312 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10352,10636,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:40:40,312 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10768,10656,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:40:40,328 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10448,10796,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:40:40,608 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20817.exe
2025-06-24 21:40:40,655 [analyzer] INFO: Injected into process with pid 9880 and name u'Unicorn-45441.exe'
2025-06-24 21:40:40,875 [analyzer] DEBUG: Loaded monitor into process with pid 11080
2025-06-24 21:40:40,905 [analyzer] DEBUG: Loaded monitor into process with pid 11128
2025-06-24 21:40:40,905 [analyzer] INFO: Injected into process with pid 10396 and name u'Unicorn-56293.exe'
2025-06-24 21:40:40,921 [analyzer] DEBUG: Loaded monitor into process with pid 11048
2025-06-24 21:40:40,921 [analyzer] INFO: Injected into process with pid 10404 and name u'Unicorn-49293.exe'
2025-06-24 21:40:40,937 [analyzer] DEBUG: Loaded monitor into process with pid 11088
2025-06-24 21:40:40,953 [analyzer] DEBUG: Loaded monitor into process with pid 11056
2025-06-24 21:40:41,078 [analyzer] INFO: Injected into process with pid 10432 and name u'Unicorn-46964.exe'
2025-06-24 21:40:41,078 [analyzer] INFO: Injected into process with pid 10664 and name u'Unicorn-14273.exe'
2025-06-24 21:40:41,078 [analyzer] INFO: Injected into process with pid 10544 and name u'Unicorn-39865.exe'
2025-06-24 21:40:41,108 [analyzer] INFO: Injected into process with pid 10552 and name u'Unicorn-664.exe'
2025-06-24 21:40:41,108 [analyzer] INFO: Injected into process with pid 10680 and name u'Unicorn-7001.exe'
2025-06-24 21:40:41,125 [analyzer] INFO: Injected into process with pid 10720 and name u'Unicorn-11201.exe'
2025-06-24 21:40:41,140 [analyzer] INFO: Injected into process with pid 10688 and name u'Unicorn-45200.exe'
2025-06-24 21:40:41,155 [analyzer] INFO: Injected into process with pid 10792 and name u'Unicorn-28672.exe'
2025-06-24 21:40:41,171 [analyzer] INFO: Injected into process with pid 11184 and name u'Unicorn-39468.exe'
2025-06-24 21:40:41,265 [analyzer] INFO: Injected into process with pid 9564 and name u'Unicorn-62341.exe'
2025-06-24 21:40:41,280 [analyzer] INFO: Injected into process with pid 9464 and name u'Unicorn-5105.exe'
2025-06-24 21:40:41,296 [analyzer] INFO: Injected into process with pid 11260 and name u'Unicorn-33868.exe'
2025-06-24 21:40:41,296 [analyzer] INFO: Injected into process with pid 9680 and name u'Unicorn-56534.exe'
2025-06-24 21:40:41,296 [analyzer] INFO: Injected into process with pid 1576 and name u'Unicorn-35003.exe'
2025-06-24 21:40:41,312 [analyzer] INFO: Injected into process with pid 9572 and name u'Unicorn-1004.exe'
2025-06-24 21:40:41,312 [analyzer] INFO: Injected into process with pid 9652 and name u'Unicorn-60576.exe'
2025-06-24 21:40:41,312 [analyzer] INFO: Injected into process with pid 11256 and name u'Unicorn-38805.exe'
2025-06-24 21:40:41,328 [analyzer] INFO: Injected into process with pid 10572 and name u'Unicorn-6132.exe'
2025-06-24 21:40:41,342 [analyzer] INFO: Injected into process with pid 9480 and name u'Unicorn-2139.exe'
2025-06-24 21:40:41,375 [analyzer] INFO: Injected into process with pid 9528 and name u'Unicorn-29668.exe'
2025-06-24 21:40:41,390 [analyzer] INFO: Injected into process with pid 11464 and name u'Unicorn-20817.exe'
2025-06-24 21:40:42,592 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16612.exe
2025-06-24 21:40:42,625 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53484.exe
2025-06-24 21:40:42,921 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-36956.exe
2025-06-24 21:40:42,983 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50362.exe
2025-06-24 21:40:43,000 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32161.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12561.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3548 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-15460.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19660.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57461.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39261.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19660.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39261.exe
2025-06-24 21:40:43,015 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19660.exe
2025-06-24 21:40:43,030 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-8361.exe
2025-06-24 21:40:43,390 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57709.exe
2025-06-24 21:40:43,390 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60774.exe
2025-06-24 21:40:43,515 [analyzer] INFO: Injected into process with pid 11776 and name u'Unicorn-16612.exe'
2025-06-24 21:40:43,530 [analyzer] INFO: Injected into process with pid 11800 and name u'Unicorn-53484.exe'
2025-06-24 21:40:47,640 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63869.exe
2025-06-24 21:40:47,655 [analyzer] INFO: Injected into process with pid 11824 and name u'Unicorn-36956.exe'
2025-06-24 21:40:47,671 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32869.exe
2025-06-24 21:40:47,717 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55642.exe
2025-06-24 21:40:47,717 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58442.exe
2025-06-24 21:40:47,765 [analyzer] INFO: Injected into process with pid 11856 and name u'Unicorn-50362.exe'
2025-06-24 21:40:47,780 [analyzer] INFO: Injected into process with pid 11848 and name u'Unicorn-50362.exe'
2025-06-24 21:40:47,796 [analyzer] INFO: Injected into process with pid 11928 and name u'Unicorn-39261.exe'
2025-06-24 21:40:47,812 [analyzer] INFO: Injected into process with pid 11920 and name u'Unicorn-19660.exe'
2025-06-24 21:40:47,812 [analyzer] INFO: Injected into process with pid 11872 and name u'Unicorn-12561.exe'
2025-06-24 21:40:47,812 [analyzer] INFO: Injected into process with pid 11864 and name u'Unicorn-32161.exe'
2025-06-24 21:40:47,828 [analyzer] INFO: Injected into process with pid 11888 and name u'Unicorn-57461.exe'
2025-06-24 21:40:47,842 [analyzer] INFO: Injected into process with pid 11912 and name u'Unicorn-8361.exe'
2025-06-24 21:40:47,858 [analyzer] INFO: Injected into process with pid 11880 and name u'Unicorn-15460.exe'
2025-06-24 21:40:47,921 [analyzer] INFO: Injected into process with pid 12084 and name u'Unicorn-57709.exe'
2025-06-24 21:40:47,921 [analyzer] INFO: Injected into process with pid 12092 and name u'Unicorn-60774.exe'
2025-06-24 21:40:48,030 [analyzer] INFO: Injected into process with pid 12224 and name u'Unicorn-63869.exe'
2025-06-24 21:40:48,062 [analyzer] INFO: Injected into process with pid 12264 and name u'Unicorn-32869.exe'
2025-06-24 21:40:48,092 [analyzer] INFO: Injected into process with pid 11416 and name u'Unicorn-55642.exe'
2025-06-24 21:40:48,108 [analyzer] INFO: Injected into process with pid 12240 and name u'Unicorn-32869.exe'
2025-06-24 21:40:48,108 [analyzer] INFO: Injected into process with pid 10992 and name u'Unicorn-58442.exe'
2025-06-24 21:40:48,842 [analyzer] INFO: Added new file to list with pid 4476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24606.exe
2025-06-24 21:40:49,296 [analyzer] INFO: Added new file to list with pid 4520 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59006.exe
2025-06-24 21:40:49,453 [analyzer] INFO: Injected into process with pid 10588 and name u'Unicorn-24606.exe'
2025-06-24 21:40:49,530 [analyzer] INFO: Injected into process with pid 10776 and name u'Unicorn-59006.exe'
2025-06-24 21:40:59,890 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30659.exe
2025-06-24 21:40:59,890 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30659.exe
2025-06-24 21:40:59,905 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30659.exe
2025-06-24 21:40:59,905 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27593.exe
2025-06-24 21:40:59,905 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45794.exe
2025-06-24 21:40:59,905 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27593.exe
2025-06-24 21:40:59,921 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32563.exe
2025-06-24 21:40:59,921 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-37028.exe
2025-06-24 21:40:59,921 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27228.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54094.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53564.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31428.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51029.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54094.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51029.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54094.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31428.exe
2025-06-24 21:40:59,953 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3692.exe
2025-06-24 21:40:59,937 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54094.exe
2025-06-24 21:41:00,187 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-36819.exe
2025-06-24 21:41:00,250 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56061.exe
2025-06-24 21:41:00,250 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13769.exe
2025-06-24 21:41:00,905 [analyzer] INFO: Added new file to list with pid 4404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5840.exe
2025-06-24 21:41:00,921 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11940,11936,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:00,921 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7587.exe
2025-06-24 21:41:00,921 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44253.exe
2025-06-24 21:41:00,921 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26052.exe
2025-06-24 21:41:00,937 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53962.exe
2025-06-24 21:41:00,953 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34348.exe
2025-06-24 21:41:00,967 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26957.exe
2025-06-24 21:41:00,967 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54692.exe
2025-06-24 21:41:00,967 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54692.exe
2025-06-24 21:41:00,967 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50492.exe
2025-06-24 21:41:01,000 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54692.exe
2025-06-24 21:41:01,000 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3329.exe
2025-06-24 21:41:01,015 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11908,11980,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,015 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11956,11972,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,046 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26865.exe
2025-06-24 21:41:01,046 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26865.exe
2025-06-24 21:41:01,046 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26865.exe
2025-06-24 21:41:01,062 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-50666.exe
2025-06-24 21:41:01,062 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-529.exe
2025-06-24 21:41:01,155 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12044,11996,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,155 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12068,12036,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,155 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12056,12048,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,155 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12028,12072,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,187 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12140,12064,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,375 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11964,12024,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,421 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12128,12124,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:01,828 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '10712,12192,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,155 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56997.exe
2025-06-24 21:41:02,171 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11000,11036,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,171 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12020,12012,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,171 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '2544,12208,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,171 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12136,12120,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,187 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '4388,12176,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,171 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12016,12008,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,187 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12200,12216,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,187 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12112,12132,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:02,842 [analyzer] INFO: Injected into process with pid 11356 and name u'Unicorn-30659.exe'
2025-06-24 21:41:02,858 [analyzer] INFO: Injected into process with pid 11444 and name u'Unicorn-53564.exe'
2025-06-24 21:41:02,875 [analyzer] INFO: Injected into process with pid 11336 and name u'Unicorn-45794.exe'
2025-06-24 21:41:02,905 [analyzer] INFO: Injected into process with pid 11436 and name u'Unicorn-51029.exe'
2025-06-24 21:41:02,905 [analyzer] INFO: Injected into process with pid 11412 and name u'Unicorn-27593.exe'
2025-06-24 21:41:02,905 [analyzer] INFO: Injected into process with pid 11396 and name u'Unicorn-32563.exe'
2025-06-24 21:41:02,905 [analyzer] INFO: Injected into process with pid 11384 and name u'Unicorn-37028.exe'
2025-06-24 21:41:02,921 [analyzer] INFO: Injected into process with pid 11588 and name u'Unicorn-27228.exe'
2025-06-24 21:41:02,921 [analyzer] INFO: Injected into process with pid 11704 and name u'Unicorn-31428.exe'
2025-06-24 21:41:02,937 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22205.exe
2025-06-24 21:41:02,983 [analyzer] INFO: Injected into process with pid 11460 and name u'Unicorn-3692.exe'
2025-06-24 21:41:02,983 [analyzer] INFO: Injected into process with pid 11708 and name u'Unicorn-54094.exe'
2025-06-24 21:41:03,062 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28744.exe
2025-06-24 21:41:03,078 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62610.exe
2025-06-24 21:41:03,140 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44888.exe
2025-06-24 21:41:03,155 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44888.exe
2025-06-24 21:41:03,155 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-16018.exe
2025-06-24 21:41:03,171 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13217.exe
2025-06-24 21:41:03,358 [analyzer] INFO: Injected into process with pid 10760 and name u'Unicorn-56997.exe'
2025-06-24 21:41:03,421 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28786.exe
2025-06-24 21:41:03,437 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59322.exe
2025-06-24 21:41:03,437 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13385.exe
2025-06-24 21:41:03,483 [analyzer] INFO: Added new file to list with pid 4520 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4985.exe
2025-06-24 21:41:03,515 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53721.exe
2025-06-24 21:41:03,515 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31586.exe
2025-06-24 21:41:03,530 [analyzer] INFO: Added new file to list with pid 4248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60456.exe
2025-06-24 21:41:03,750 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11284,11304,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11792,11328,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11228,12292,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11324,11476,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,780 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11520,12252,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,780 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11768,12080,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,796 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12312,12316,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,796 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12260,11728,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,796 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12104,11836,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,796 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12296,12300,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,796 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11652,11812,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:03,812 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12304,12308,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:04,030 [analyzer] INFO: Added new file to list with pid 4476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13428.exe
2025-06-24 21:41:04,030 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21828.exe
2025-06-24 21:41:04,078 [analyzer] INFO: Injected into process with pid 11820 and name u'Unicorn-22205.exe'
2025-06-24 21:41:04,342 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46285.exe
2025-06-24 21:41:04,342 [analyzer] INFO: Injected into process with pid 11788 and name u'Unicorn-28744.exe'
2025-06-24 21:41:04,342 [analyzer] INFO: Injected into process with pid 2916 and name u'Unicorn-62610.exe'
2025-06-24 21:41:04,405 [analyzer] INFO: Injected into process with pid 1484 and name u'Unicorn-44888.exe'
2025-06-24 21:41:04,405 [analyzer] INFO: Injected into process with pid 12144 and name u'Unicorn-13217.exe'
2025-06-24 21:41:04,421 [analyzer] INFO: Injected into process with pid 1548 and name u'Unicorn-44888.exe'
2025-06-24 21:41:04,421 [analyzer] INFO: Injected into process with pid 11944 and name u'Unicorn-16018.exe'
2025-06-24 21:41:04,546 [analyzer] INFO: Injected into process with pid 2336 and name u'Unicorn-28786.exe'
2025-06-24 21:41:04,562 [analyzer] INFO: Injected into process with pid 11352 and name u'Unicorn-28786.exe'
2025-06-24 21:41:04,592 [analyzer] INFO: Injected into process with pid 7696 and name u'Unicorn-59322.exe'
2025-06-24 21:41:04,592 [analyzer] INFO: Injected into process with pid 11556 and name u'Unicorn-28786.exe'
2025-06-24 21:41:04,592 [analyzer] INFO: Injected into process with pid 11608 and name u'Unicorn-13385.exe'
2025-06-24 21:41:04,780 [analyzer] INFO: Injected into process with pid 12612 and name u'Unicorn-21828.exe'
2025-06-24 21:41:04,796 [analyzer] INFO: Injected into process with pid 12604 and name u'Unicorn-13428.exe'
2025-06-24 21:41:05,046 [analyzer] INFO: Injected into process with pid 12720 and name u'Unicorn-46285.exe'
2025-06-24 21:41:06,312 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30812.exe
2025-06-24 21:41:06,312 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30812.exe
2025-06-24 21:41:06,312 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-30812.exe
2025-06-24 21:41:06,687 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-233.exe
2025-06-24 21:41:06,687 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-233.exe
2025-06-24 21:41:06,765 [analyzer] INFO: Injected into process with pid 12800 and name u'Unicorn-30812.exe'
2025-06-24 21:41:07,000 [analyzer] INFO: Injected into process with pid 12832 and name u'Unicorn-233.exe'
2025-06-24 21:41:13,671 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54436.exe
2025-06-24 21:41:13,671 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23901.exe
2025-06-24 21:41:13,671 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54436.exe
2025-06-24 21:41:13,780 [analyzer] INFO: Added new file to list with pid 4564 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12482.exe
2025-06-24 21:41:13,967 [analyzer] INFO: Injected into process with pid 12896 and name u'Unicorn-23901.exe'
2025-06-24 21:41:14,015 [analyzer] INFO: Injected into process with pid 12908 and name u'Unicorn-54436.exe'
2025-06-24 21:41:14,062 [analyzer] INFO: Injected into process with pid 12948 and name u'Unicorn-12482.exe'
2025-06-24 21:41:23,530 [analyzer] INFO: Added new file to list with pid 3324 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38370.exe
2025-06-24 21:41:26,250 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-17460.exe
2025-06-24 21:41:26,250 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42661.exe
2025-06-24 21:41:26,265 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60861.exe
2025-06-24 21:41:26,280 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23060.exe
2025-06-24 21:41:26,312 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-58061.exe
2025-06-24 21:41:26,312 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-18860.exe
2025-06-24 21:41:26,328 [analyzer] INFO: Added new file to list with pid 4404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53861.exe
2025-06-24 21:41:26,342 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45726.exe
2025-06-24 21:41:26,358 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24195.exe
2025-06-24 21:41:26,421 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-568.exe
2025-06-24 21:41:26,437 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19033.exe
2025-06-24 21:41:26,437 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-37234.exe
2025-06-24 21:41:26,437 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64970.exe
2025-06-24 21:41:26,483 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34434.exe
2025-06-24 21:41:26,530 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25197.exe
2025-06-24 21:41:26,546 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55732.exe
2025-06-24 21:41:26,562 [analyzer] INFO: Added new file to list with pid 3784 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55732.exe
2025-06-24 21:41:26,562 [analyzer] INFO: Added new file to list with pid 2932 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27997.exe
2025-06-24 21:41:26,592 [analyzer] INFO: Added new file to list with pid 3904 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9796.exe
2025-06-24 21:41:26,687 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55682.exe
2025-06-24 21:41:26,703 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-37482.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-37482.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59981.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 3248 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59981.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 3792 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5281.exe
2025-06-24 21:41:26,733 [analyzer] INFO: Added new file to list with pid 4520 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42817.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55682.exe
2025-06-24 21:41:26,733 [analyzer] INFO: Added new file to list with pid 2360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52882.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 2956 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52882.exe
2025-06-24 21:41:26,717 [analyzer] INFO: Added new file to list with pid 4000 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26115.exe
2025-06-24 21:41:26,733 [analyzer] INFO: Added new file to list with pid 1840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19380.exe
2025-06-24 21:41:26,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13216,13220,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13112,13116,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13152,13156,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,765 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13168,13172,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 713, in _communicate
    stderr_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,780 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13224,13228,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,780 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13232,13236,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,812 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12532,12536,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,812 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13240,13244,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,828 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '12540,12544,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,828 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '13272,13276,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:26,828 [analyzer] ERROR: Pipe command handler exception occurred (command PROCESS2 args '11684,10512,0').
Traceback (most recent call last):
  File "C:/tmp4w2pkt/analyzer.py", line 412, in dispatch
    response = fn(arguments)
  File "C:/tmp4w2pkt/analyzer.py", line 314, in _handle_process2
    return self._inject_process(int(pid), int(tid), int(mode))
  File "C:/tmp4w2pkt/analyzer.py", line 282, in _inject_process
    proc.inject(dll, apc=True, mode="%s" % mode)
  File "C:\tmp4w2pkt\lib\api\process.py", line 440, in inject
    is32bit = self.is32bit(pid=self.pid)
  File "C:\tmp4w2pkt\lib\api\process.py", line 272, in is32bit
    bitsize = int(subprocess_checkoutput(args))
  File "C:\tmp4w2pkt\lib\api\process.py", line 105, in subprocess_checkoutput
    args, stdin=subprocess.PIPE, stderr=subprocess.PIPE, env=env,
  File "C:\Python27\lib\subprocess.py", line 213, in check_output
    output, unused_err = process.communicate()
  File "C:\Python27\lib\subprocess.py", line 479, in communicate
    return self._communicate(input)
  File "C:\Python27\lib\subprocess.py", line 707, in _communicate
    stdout_thread.start()
  File "C:\Python27\lib\threading.py", line 736, in start
    _start_new_thread(self.__bootstrap, ())
error: can't start new thread
2025-06-24 21:41:27,030 [analyzer] INFO: Added new file to list with pid 3448 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11513.exe
2025-06-24 21:41:27,030 [analyzer] INFO: Added new file to list with pid 3752 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12913.exe
2025-06-24 21:41:27,030 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2276.exe
2025-06-24 21:41:27,062 [analyzer] INFO: Added new file to list with pid 3356 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3657.exe
2025-06-24 21:41:27,078 [analyzer] INFO: Injected into process with pid 13032 and name u'Unicorn-38370.exe'
2025-06-24 21:41:27,092 [analyzer] INFO: Added new file to list with pid 712 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21858.exe
2025-06-24 21:41:27,092 [analyzer] INFO: Added new file to list with pid 3936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42493.exe
2025-06-24 21:41:27,092 [analyzer] INFO: Added new file to list with pid 2404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-19058.exe
2025-06-24 21:41:27,092 [analyzer] INFO: Added new file to list with pid 3584 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43993.exe
2025-06-24 21:41:27,108 [analyzer] INFO: Added new file to list with pid 3900 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1892.exe
2025-06-24 21:41:27,125 [analyzer] INFO: Added new file to list with pid 3940 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7492.exe
2025-06-24 21:41:27,203 [analyzer] INFO: Added new file to list with pid 4476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-51452.exe
2025-06-24 21:41:27,203 [analyzer] INFO: Added new file to list with pid 3352 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22316.exe
2025-06-24 21:41:27,217 [analyzer] INFO: Added new file to list with pid 2820 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62826.exe
2025-06-24 21:41:27,233 [analyzer] INFO: Added new file to list with pid 292 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13252.exe
2025-06-24 21:41:27,250 [analyzer] INFO: Added new file to list with pid 3580 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54988.exe
2025-06-24 21:41:27,296 [analyzer] INFO: Added new file to list with pid 3508 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28653.exe
2025-06-24 21:41:27,390 [analyzer] INFO: Added new file to list with pid 4224 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31732.exe
2025-06-24 21:41:27,703 [analyzer] INFO: Added new file to list with pid 4312 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33998.exe
2025-06-24 21:41:27,780 [analyzer] INFO: Injected into process with pid 13160 and name u'Unicorn-45726.exe'
2025-06-24 21:41:27,796 [analyzer] INFO: Injected into process with pid 13064 and name u'Unicorn-17460.exe'
2025-06-24 21:41:27,796 [analyzer] INFO: Injected into process with pid 13128 and name u'Unicorn-18860.exe'
2025-06-24 21:41:27,796 [analyzer] INFO: Injected into process with pid 13176 and name u'Unicorn-24195.exe'
2025-06-24 21:41:27,812 [analyzer] INFO: Injected into process with pid 13120 and name u'Unicorn-58061.exe'
2025-06-24 21:41:27,812 [analyzer] INFO: Injected into process with pid 13072 and name u'Unicorn-42661.exe'
2025-06-24 21:41:27,812 [analyzer] INFO: Injected into process with pid 13096 and name u'Unicorn-42661.exe'
2025-06-24 21:41:27,828 [analyzer] INFO: Injected into process with pid 13144 and name u'Unicorn-18860.exe'
2025-06-24 21:41:27,828 [analyzer] INFO: Injected into process with pid 13080 and name u'Unicorn-60861.exe'
2025-06-24 21:41:27,842 [analyzer] INFO: Injected into process with pid 13088 and name u'Unicorn-23060.exe'
2025-06-24 21:41:27,875 [analyzer] INFO: Injected into process with pid 13136 and name u'Unicorn-53861.exe'
2025-06-24 21:41:27,875 [analyzer] INFO: Injected into process with pid 13104 and name u'Unicorn-60861.exe'
2025-06-24 21:41:28,217 [analyzer] INFO: Added new file to list with pid 4564 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11780.exe
2025-06-24 21:41:28,217 [analyzer] INFO: Added new file to list with pid 3220 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38381.exe
2025-06-24 21:41:28,233 [analyzer] INFO: Added new file to list with pid 3748 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60516.exe
2025-06-24 21:41:29,546 [analyzer] INFO: Added new file to list with pid 4092 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34236.exe
2025-06-24 21:41:29,625 [analyzer] INFO: Added new file to list with pid 3948 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26845.exe
2025-06-24 21:41:30,046 [analyzer] INFO: Added new file to list with pid 4068 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65485.exe
2025-06-24 21:41:30,078 [analyzer] INFO: Added new file to list with pid 3736 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29821.exe
2025-06-24 21:41:30,078 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-14420.exe
2025-06-24 21:41:30,078 [analyzer] INFO: Added new file to list with pid 3004 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-54756.exe
2025-06-24 21:41:42,671 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21377.exe
2025-06-24 21:41:42,671 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-53578.exe
2025-06-24 21:41:42,671 [analyzer] INFO: Added new file to list with pid 1860 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21377.exe
2025-06-24 21:41:42,687 [analyzer] INFO: Added new file to list with pid 4404 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56113.exe
2025-06-24 21:41:42,687 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33977.exe
2025-06-24 21:41:42,703 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28377.exe
2025-06-24 21:41:42,703 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29777.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3441.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6241.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3441.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28377.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3441.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28377.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6241.exe
2025-06-24 21:41:42,733 [analyzer] INFO: Added new file to list with pid 3800 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-35112.exe
2025-06-24 21:41:42,733 [analyzer] INFO: Added new file to list with pid 3144 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6241.exe
2025-06-24 21:41:42,733 [analyzer] INFO: Added new file to list with pid 2812 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28377.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3660 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-3441.exe
2025-06-24 21:41:42,717 [analyzer] INFO: Added new file to list with pid 3804 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-29777.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24356.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39757.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24356.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39757.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3688 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4756.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64693.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57692.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 4024 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42557.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3396 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39757.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 1260 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-60227.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57692.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3340 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57692.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39757.exe
2025-06-24 21:41:45,875 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64693.exe
2025-06-24 21:41:45,890 [analyzer] INFO: Added new file to list with pid 2108 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-64693.exe
2025-06-24 21:41:49,078 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11865.exe
2025-06-24 21:41:49,078 [analyzer] INFO: Added new file to list with pid 2348 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11865.exe
2025-06-24 21:41:49,078 [analyzer] INFO: Added new file to list with pid 2240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-4865.exe
2025-06-24 21:41:49,078 [analyzer] INFO: Added new file to list with pid 1988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7399.exe
2025-06-24 21:41:49,078 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-7399.exe
2025-06-24 21:41:49,092 [analyzer] INFO: Added new file to list with pid 3388 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52466.exe
2025-06-24 21:41:49,140 [analyzer] INFO: Added new file to list with pid 3592 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-28300.exe
2025-06-24 21:41:52,217 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-44255.exe
2025-06-24 21:41:52,217 [analyzer] INFO: Added new file to list with pid 3296 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65521.exe
2025-06-24 21:41:55,342 [analyzer] INFO: Added new file to list with pid 3184 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43334.exe
2025-06-24 21:42:39,875 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:42:58,703 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2820.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 1860.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3004.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 292.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 1260.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2108.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2812.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2404.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2932.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2956.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 712.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2240.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2348.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 1988.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 1840.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 2360.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3144.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3184.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3248.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3296.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3340.
2025-06-24 21:42:58,717 [lib.api.process] INFO: Successfully terminated process with pid 3356.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3388.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3448.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3508.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3540.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3548.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3640.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3660.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3688.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3752.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3784.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3904.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3940.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3948.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 4024.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 4068.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 4092.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3220.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3324.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3396.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3584.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3560.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3580.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3592.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3604.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3736.
2025-06-24 21:42:58,733 [lib.api.process] INFO: Successfully terminated process with pid 3900.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3352.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3800.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3748.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3936.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4016.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4000.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3792.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3804.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4224.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4248.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4312.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4404.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4476.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4520.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4564.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4608.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4644.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4652.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4724.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4732.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4816.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4864.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4916.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4924.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4984.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4992.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4976.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 5028.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 5088.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3476.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 3776.
2025-06-24 21:42:58,750 [lib.api.process] INFO: Successfully terminated process with pid 4104.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4240.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4332.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 2056.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 1816.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4416.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4436.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 3712.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5024.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4180.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4152.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5004.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 2912.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 4972.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5124.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5140.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5132.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5292.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5300.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5376.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5484.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5532.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5524.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5492.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5636.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5664.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5672.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5656.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5792.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5800.
2025-06-24 21:42:58,765 [lib.api.process] INFO: Successfully terminated process with pid 5892.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5900.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5920.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6000.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6056.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6064.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6136.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5256.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5272.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5508.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5568.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5560.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 596.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5780.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5836.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5844.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5972.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5936.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5980.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5516.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5504.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5652.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6088.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5840.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5860.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5688.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5356.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 5696.
2025-06-24 21:42:58,780 [lib.api.process] INFO: Successfully terminated process with pid 6164.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6176.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6328.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6448.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6460.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6536.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6636.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6652.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6660.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6676.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6808.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6880.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6896.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6888.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6972.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 7004.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6964.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6988.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6980.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 7016.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6996.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 7024.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 7032.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 7084.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6188.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6224.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6192.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6272.
2025-06-24 21:42:58,796 [lib.api.process] INFO: Successfully terminated process with pid 6348.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 2024.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 372.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6868.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7120.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6360.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 1280.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6708.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 1176.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 2148.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6756.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 2864.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6944.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 348.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6876.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 1384.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 6872.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7228.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7264.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7288.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7296.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7280.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7304.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7400.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7416.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7432.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7408.
2025-06-24 21:42:58,812 [lib.api.process] INFO: Successfully terminated process with pid 7424.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7788.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7796.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7816.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7808.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8000.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8040.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8056.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8020.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8048.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8012.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 8188.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 6512.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 2204.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7240.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7172.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7256.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7532.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7536.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7540.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7632.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7516.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7608.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7600.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7644.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7576.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7880.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7868.
2025-06-24 21:42:58,828 [lib.api.process] INFO: Successfully terminated process with pid 7908.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8080.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 6748.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8124.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8108.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8148.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8132.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8216.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8224.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8240.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8232.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8248.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8260.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8268.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8308.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8364.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8372.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8340.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8332.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8408.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8400.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8488.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8540.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8580.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8672.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8688.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8736.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8760.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8844.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8932.
2025-06-24 21:42:58,842 [lib.api.process] INFO: Successfully terminated process with pid 8956.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 8976.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9024.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9108.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 2096.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9140.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 7392.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9104.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 8556.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 7892.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9072.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9160.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 3032.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 8440.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 7936.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 804.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 7476.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9016.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 8116.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 8072.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 2540.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9248.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9320.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9368.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9304.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9336.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9312.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9256.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9328.
2025-06-24 21:42:58,858 [lib.api.process] INFO: Successfully terminated process with pid 9272.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9360.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9352.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9264.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9296.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9344.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9280.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9288.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9384.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9376.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9868.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9888.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9900.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10020.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10028.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10044.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10108.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9748.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10080.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10152.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9924.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9824.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10188.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9400.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10120.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9232.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9936.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9620.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10244.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 9840.
2025-06-24 21:42:58,875 [lib.api.process] INFO: Successfully terminated process with pid 10260.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 9716.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10252.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10268.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 9876.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10332.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10340.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10384.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10972.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11056.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11128.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11040.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11072.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11096.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11080.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11048.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11088.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11064.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11104.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11112.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11136.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 11120.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 9880.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10404.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10396.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10432.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10664.
2025-06-24 21:42:58,890 [lib.api.process] INFO: Successfully terminated process with pid 10544.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10552.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10680.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10792.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10688.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10720.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11184.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10572.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9680.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 1576.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9528.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9652.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11260.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9464.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9564.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9572.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 9480.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11256.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10736.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10780.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10352.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10768.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 10448.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11464.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11776.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11800.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11824.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11848.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11856.
2025-06-24 21:42:58,905 [lib.api.process] INFO: Successfully terminated process with pid 11872.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11864.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11880.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11888.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11912.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11920.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11928.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 12084.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 12092.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 12224.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 12240.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 12264.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11416.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 10992.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 10588.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 10776.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11356.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11336.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11396.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11708.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11412.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11436.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11460.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11704.
2025-06-24 21:42:58,921 [lib.api.process] INFO: Successfully terminated process with pid 11384.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11588.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11444.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11940.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11908.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11956.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12044.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12068.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12028.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12056.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12140.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11964.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12128.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 4388.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12020.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12112.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12016.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12136.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11000.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12200.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 2544.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 10712.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 10760.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11820.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11788.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 2916.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 1548.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11944.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 12144.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 1484.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11352.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 2336.
2025-06-24 21:42:58,937 [lib.api.process] INFO: Successfully terminated process with pid 11608.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 7696.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11556.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11324.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12104.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12260.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11284.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11520.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11792.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11768.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11228.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12312.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 11652.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12296.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12304.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12604.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12612.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12720.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12800.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12832.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12896.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12908.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 12948.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13032.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13080.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13088.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13064.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13072.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13128.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13136.
2025-06-24 21:42:58,953 [lib.api.process] INFO: Successfully terminated process with pid 13096.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13120.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13104.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13144.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13176.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13152.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13168.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13112.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13160.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13216.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13224.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13232.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13272.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 13240.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 12532.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 12540.
2025-06-24 21:42:58,967 [lib.api.process] INFO: Successfully terminated process with pid 11684.
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23195.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-17460.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-3029.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40989.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24155.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41678.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62341.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54808.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-17708.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45900.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41382.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7587.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7399.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23595.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6552.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33449.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42150.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1118.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56192.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-63888.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30006.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-14420.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6878.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54996.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45441.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-63869.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43334.exe
2025-06-24 21:42:59,187 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-8361.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26031.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50666.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40197.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11201.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-16612.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32161.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61362.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-2139.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5649.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62679.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-47035.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5840.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13252.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40772.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53484.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30812.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-65521.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13217.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46964.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6241.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54436.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-16101.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43289.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-8472.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-3061.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10331.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46535.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-12645.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50508.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55372.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39757.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34348.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41333.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41679.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-15571.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-44253.exe
2025-06-24 21:42:59,203 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7492.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33519.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53188.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31428.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45794.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27554.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4412.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-44255.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10255.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-47967.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6132.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11164.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57064.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24821.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24436.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-846.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6217.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26725.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-9240.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7001.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60516.exe
2025-06-24 21:42:59,217 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27228.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26166.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-14273.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51501.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55682.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32563.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-3441.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-110.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-12561.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39865.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39932.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24614.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29777.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-14718.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56089.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29668.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20344.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51029.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13910.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56061.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39261.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46285.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60576.exe
2025-06-24 21:42:59,233 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19301.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-36443.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43180.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13428.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-44021.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33868.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29753.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62826.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-8504.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7838.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7422.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29821.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58442.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41732.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-47846.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26052.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57692.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54094.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52466.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29284.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56293.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60108.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34808.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11865.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-22316.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-319.exe
2025-06-24 21:42:59,250 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31879.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59179.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48204.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19380.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-64693.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34243.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11780.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10710.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-999.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5062.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13591.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1750.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1892.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58825.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25769.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-2499.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51718.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20780.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50492.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4985.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-2739.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-49574.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61852.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6532.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40968.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59322.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59283.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30600.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28480.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48656.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-64970.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6799.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26757.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29592.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-18860.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21689.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31732.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56997.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53564.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6969.exe
2025-06-24 21:42:59,265 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41700.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13595.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58023.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59942.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56352.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-44288.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55335.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48844.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26115.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19033.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58061.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10415.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57709.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57461.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19730.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33852.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24237.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19829.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59426.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50752.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-18245.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42646.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1004.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56534.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13471.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60783.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7907.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23901.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48825.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21858.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40742.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50124.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58902.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38527.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-36681.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34774.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48895.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48533.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13326.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51533.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13385.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35426.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28300.exe
2025-06-24 21:42:59,280 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28377.exe
2025-06-24 21:42:59,296 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-9796.exe
2025-06-24 21:42:59,296 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50362.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23980.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28786.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23806.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60227.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-36819.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-15566.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60456.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38370.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25132.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33184.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-2030.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-16470.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55561.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6418.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10732.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42557.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35345.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-37234.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42442.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35003.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29861.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51744.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62610.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-16325.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-37482.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30659.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1180.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31145.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54111.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53861.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43993.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-12913.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20817.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55642.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52371.exe
2025-06-24 21:42:59,312 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19375.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-9830.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-14390.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24356.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30095.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54988.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11580.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-231.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-18978.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52641.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5903.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13510.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51268.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41260.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-15890.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5105.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38805.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27593.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25197.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27173.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54599.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42531.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34434.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10155.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5281.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4865.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10245.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33977.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53910.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39468.exe
2025-06-24 21:42:59,328 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-3692.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13769.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32623.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11867.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-30392.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26865.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42415.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32806.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58675.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-49293.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21828.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19058.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20331.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32869.exe
2025-06-24 21:42:59,342 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-529.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24606.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-65194.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59053.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41112.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-36956.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45500.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-47067.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-50884.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43227.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45726.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4756.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56671.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-51302.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13992.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59607.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53962.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11272.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-17715.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4550.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62063.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6144.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-4478.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56909.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-64071.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52882.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13583.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61200.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31730.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42661.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21377.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13698.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28453.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-37028.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27951.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27675.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52284.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55732.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24456.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-44888.exe
2025-06-24 21:42:59,358 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54756.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54144.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21083.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-631.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35248.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-1809.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-12482.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13022.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24195.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39071.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-64797.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-65312.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19976.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46607.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41599.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33304.exe
2025-06-24 21:42:59,375 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33998.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27997.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13224.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-39553.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29771.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57133.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28576.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26845.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13061.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26957.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34236.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-47304.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-29774.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-22205.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-233.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-2276.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-15460.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-17553.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57597.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53008.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52535.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-52856.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55827.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55753.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35148.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19660.exe
2025-06-24 21:42:59,390 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28672.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-568.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42493.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34832.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-16018.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42791.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32661.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11513.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24461.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-14581.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46286.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-54692.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-19506.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-21153.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-40492.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60347.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57731.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42974.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38381.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-664.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35391.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35088.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55439.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-60861.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56113.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59981.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-10629.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53578.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61702.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-33953.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56619.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-58242.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42817.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-31586.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7924.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-55141.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-35112.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23060.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-3657.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26753.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-28653.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-7465.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-53721.exe
2025-06-24 21:42:59,405 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-45200.exe
2025-06-24 21:42:59,421 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13243.exe
2025-06-24 21:42:59,421 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46774.exe
2025-06-24 21:42:59,421 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-07-02 12:20:22,990 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:24,012 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:25,030 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:26,048 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:27,066 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:28,084 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:29,102 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:30,128 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:31,572 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:32,599 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:33,630 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:34,658 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:35,697 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:36,765 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:37,794 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:38,812 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:39,831 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:40,852 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:41,869 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:42,900 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:44,027 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:45,128 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:46,190 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:47,246 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:48,293 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:49,332 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:50,351 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:51,375 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:52,419 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:53,454 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:54,477 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:55,494 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:56,512 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:57,534 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:58,562 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:20:59,582 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:00,605 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:01,626 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:02,646 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:03,663 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:04,685 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:05,708 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:06,749 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:07,833 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:08,872 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:09,896 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:10,943 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:11,986 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:13,027 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:14,244 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:15,349 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:16,424 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:17,471 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:18,534 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:19,607 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:20,672 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:21,757 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:22,811 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:23,865 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:24,926 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:25,992 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:27,102 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:28,241 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:29,296 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:30,367 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:31,431 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:32,483 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:33,544 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:34,623 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:35,670 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:36,697 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:38,031 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:39,291 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:40,347 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:41,376 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:42,575 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:43,640 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:44,917 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:46,180 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:47,247 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:48,286 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:49,648 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:50,693 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:51,744 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:52,779 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:53,811 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:54,934 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:55,965 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:56,998 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:58,038 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:21:59,063 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:00,093 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:01,123 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:02,166 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:03,247 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:04,288 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:05,346 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:06,373 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:07,401 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:08,436 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:09,469 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:10,517 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:11,542 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:12,572 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:13,601 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:14,642 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:16,064 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:17,098 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:18,126 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:19,661 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:20,932 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:22,137 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:23,190 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:24,234 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:25,278 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:26,323 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:27,529 [cuckoo.core.scheduler] DEBUG: Task #6631181: no machine available yet
2025-07-02 12:22:28,855 [cuckoo.core.scheduler] INFO: Task #6631181: acquired machine win7x6423 (label=win7x6423)
2025-07-02 12:22:28,859 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.223 for task #6631181
2025-07-02 12:22:29,256 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2762043 (interface=vboxnet0, host=192.168.168.223)
2025-07-02 12:22:29,949 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6423
2025-07-02 12:22:37,421 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6423 to vmcloak
2025-07-02 12:24:08,940 [cuckoo.core.guest] INFO: Starting analysis #6631181 on guest (id=win7x6423, ip=192.168.168.223)
2025-07-02 12:24:09,946 [cuckoo.core.guest] DEBUG: win7x6423: not ready yet
2025-07-02 12:24:14,992 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6423, ip=192.168.168.223)
2025-07-02 12:24:15,111 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6423, ip=192.168.168.223, monitor=latest, size=6660546)
2025-07-02 12:24:16,311 [cuckoo.core.resultserver] DEBUG: Task #6631181: live log analysis.log initialized.
2025-07-02 12:24:17,190 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:17,652 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:18,459 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0001.jpg'
2025-07-02 12:24:18,477 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 133480
2025-07-02 12:24:20,956 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:24,397 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:24,413 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:27,757 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:27,770 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:27,772 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:27,850 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,031 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:24:31,691 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,695 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,697 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,697 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,699 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,760 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,882 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:31,883 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:34,505 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,061 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,099 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,103 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,280 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,319 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,418 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,540 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,787 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,806 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:35,867 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:36,138 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:36,177 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:36,208 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:36,241 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:36,318 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:38,036 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:38,209 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:38,309 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:38,766 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:39,023 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:39,083 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:39,113 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:39,473 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:40,224 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:40,292 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,446 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0002.jpg'
2025-07-02 12:24:41,463 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 68184
2025-07-02 12:24:41,566 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,567 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,601 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,611 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,614 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,625 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:41,637 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:42,143 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:42,769 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0003.jpg'
2025-07-02 12:24:42,814 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:42,838 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 114636
2025-07-02 12:24:42,842 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:43,864 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0004.jpg'
2025-07-02 12:24:43,879 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 64469
2025-07-02 12:24:43,975 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:44,019 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:44,035 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:44,493 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:44,496 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:44,654 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:45,021 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:45,084 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:46,179 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0005.jpg'
2025-07-02 12:24:46,214 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 116648
2025-07-02 12:24:46,520 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:24:47,191 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:47,332 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0006.jpg'
2025-07-02 12:24:47,340 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 66340
2025-07-02 12:24:47,581 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:47,852 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:48,386 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:49,628 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:49,835 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:49,837 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:50,253 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:50,284 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:50,597 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:50,852 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:52,890 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:52,941 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,184 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,199 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,201 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,269 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,442 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,460 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,633 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,645 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,822 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,824 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,829 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,832 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,857 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:53,966 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:54,517 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:54,538 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:54,574 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:24:54,581 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,041 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,141 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0007.jpg'
2025-07-02 12:25:00,162 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 77322
2025-07-02 12:25:00,802 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,865 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,874 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,938 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:00,976 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:01,366 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:01,368 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:01,369 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0008.jpg'
2025-07-02 12:25:01,383 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 137503
2025-07-02 12:25:01,729 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:01,787 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:25:03,204 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,351 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,419 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,490 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,884 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,894 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:03,948 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:04,297 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:04,410 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:04,472 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:04,965 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:04,969 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,003 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,567 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,571 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,643 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,739 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:05,895 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:06,744 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:06,760 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:06,766 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:06,767 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:06,768 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,207 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,269 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,302 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,327 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,368 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,440 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,733 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,767 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:07,864 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,633 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,675 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,691 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,722 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,727 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:08,745 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:09,012 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:09,028 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:09,113 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:09,754 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:09,770 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:15,253 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:15,554 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:15,556 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:15,612 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:15,675 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:17,058 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:25:22,510 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0009.jpg'
2025-07-02 12:25:22,521 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 67944
2025-07-02 12:25:25,275 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,278 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0010.jpg'
2025-07-02 12:25:25,288 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 77322
2025-07-02 12:25:25,552 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,569 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,618 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,772 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,786 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,789 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,803 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,805 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,818 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,824 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,831 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,851 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,865 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,885 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,903 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,915 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:25,957 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:26,030 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,176 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,195 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,223 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,584 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,629 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,770 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,782 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,832 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,863 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,864 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:27,926 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:28,455 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:28,457 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:28,475 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:28,505 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:28,612 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:29,229 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:30,128 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:30,192 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:30,193 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:30,254 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:30,333 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:32,134 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:25:35,693 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:35,694 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:35,720 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:35,729 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:35,757 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:42,969 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:43,010 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:43,034 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0011.jpg'
2025-07-02 12:25:43,048 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 67944
2025-07-02 12:25:43,060 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:43,129 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:47,288 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:25:59,316 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,326 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,328 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,331 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,332 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,336 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,338 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,339 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,340 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,341 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,343 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,344 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,350 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,353 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,359 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,529 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,560 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,572 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,595 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,597 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,599 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,600 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,601 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,604 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,605 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,607 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,630 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,650 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,680 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,695 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,700 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,720 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,721 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,722 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,723 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,724 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,725 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,725 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,726 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,730 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,731 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,732 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0012.jpg'
2025-07-02 12:25:59,734 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 77322
2025-07-02 12:25:59,735 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,736 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,737 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,738 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,739 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,740 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,741 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,744 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,746 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,748 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,750 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,751 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,756 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,772 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,773 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:25:59,785 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:01,243 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:01,510 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:01,785 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:02,729 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:26:02,931 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0013.jpg'
2025-07-02 12:26:02,949 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 73271
2025-07-02 12:26:09,150 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0014.jpg'
2025-07-02 12:26:09,161 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 64398
2025-07-02 12:26:18,110 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:26:19,199 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,221 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,280 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,349 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,380 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,396 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,443 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,444 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,474 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,489 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,491 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,492 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,519 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,521 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,555 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,566 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,568 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,615 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,683 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,707 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,833 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,834 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:19,861 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,047 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,049 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0015.jpg'
2025-07-02 12:26:20,052 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,053 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,054 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,055 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,061 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 74199
2025-07-02 12:26:20,066 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,082 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,145 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,270 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,296 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,431 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,492 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,513 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,553 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,613 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,637 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:20,868 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,264 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,271 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,271 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0016.jpg'
2025-07-02 12:26:21,274 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,283 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 134364
2025-07-02 12:26:21,286 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,310 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,316 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,331 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,388 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,539 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,549 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,550 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,552 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,553 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,554 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,554 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,555 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,556 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,557 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,597 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:21,599 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:23,741 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:30,645 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0017.jpg'
2025-07-02 12:26:30,657 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 64795
2025-07-02 12:26:33,337 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:26:43,894 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0018.jpg'
2025-07-02 12:26:44,329 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 134364
2025-07-02 12:26:45,134 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,136 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,137 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,152 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,160 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,194 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,219 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,222 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,257 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:45,276 [cuckoo.core.resultserver] DEBUG: Task #6631181 is sending a BSON stream
2025-07-02 12:26:48,475 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:26:53,010 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'shots/0019.jpg'
2025-07-02 12:26:53,019 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 64795
2025-07-02 12:27:03,598 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:27:18,883 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:27:34,276 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:27:49,457 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:28:04,679 [cuckoo.core.guest] DEBUG: win7x6423: analysis #6631181 still processing
2025-07-02 12:28:07,684 [cuckoo.core.guest] INFO: win7x6423: end of analysis reached!
2025-07-02 12:28:07,700 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:28:07,727 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:28:08,740 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6423 to path /srv/cuckoo/cwd/storage/analyses/6631181/memory.dmp
2025-07-02 12:28:08,755 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6423
2025-07-02 12:28:52,757 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'curtain/1750794168.34.curtain.log'
2025-07-02 12:28:52,760 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 36
2025-07-02 12:29:02,339 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'sysmon/1750794176.89.sysmon.xml'
2025-07-02 12:29:03,042 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 21244514
2025-07-02 12:29:03,302 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/a666edbd4fe49817_unicorn-27036.exe'
2025-07-02 12:29:03,307 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479332
2025-07-02 12:29:03,310 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/f770866ac1f6831a_unicorn-38672.exe'
2025-07-02 12:29:03,315 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479336
2025-07-02 12:29:03,318 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/f3dea8895f421c00_unicorn-63387.exe'
2025-07-02 12:29:03,329 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/788e7a9cbbb969c3_unicorn-52486.exe'
2025-07-02 12:29:03,346 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,350 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/26a920670b868ae3_unicorn-48468.exe'
2025-07-02 12:29:03,375 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,377 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/096fdbb55b756ee9_unicorn-7253.exe'
2025-07-02 12:29:03,380 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,384 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/4f3132e05bb01719_unicorn-3329.exe'
2025-07-02 12:29:03,386 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/4c04a531b5d53206_unicorn-57890.exe'
2025-07-02 12:29:03,388 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/2ac3d9b8b83a43cc_unicorn-58745.exe'
2025-07-02 12:29:03,391 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/84f9058995533980_unicorn-34066.exe'
2025-07-02 12:29:03,394 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/0a72e3af7872e01d_unicorn-19771.exe'
2025-07-02 12:29:03,396 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/2cafea3998ea1fb7_unicorn-38633.exe'
2025-07-02 12:29:03,401 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479336
2025-07-02 12:29:03,405 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,408 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,411 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479336
2025-07-02 12:29:03,414 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/1cad1a09c190ca45_unicorn-22940.exe'
2025-07-02 12:29:03,424 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479331
2025-07-02 12:29:03,427 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479333
2025-07-02 12:29:03,429 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,432 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/ec004d7e7a7dbcca_unicorn-26284.exe'
2025-07-02 12:29:03,434 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/192200b20c37018f_unicorn-38750.exe'
2025-07-02 12:29:03,437 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/3cfd001be4cea7e7_unicorn-28744.exe'
2025-07-02 12:29:03,439 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/51becadbef012f03_unicorn-59006.exe'
2025-07-02 12:29:03,443 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,445 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,448 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,636 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479337
2025-07-02 12:29:03,645 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/0562b0bb38a956f3_unicorn-51452.exe'
2025-07-02 12:29:03,670 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,673 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/a6133707c07219e0_unicorn-65485.exe'
2025-07-02 12:29:03,684 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/facb641c64840cfa_unicorn-39074.exe'
2025-07-02 12:29:03,687 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/d28b079e2e13fd7b_unicorn-19089.exe'
2025-07-02 12:29:03,690 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/2cf8571d063051dc_unicorn-42931.exe'
2025-07-02 12:29:03,693 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/8076fd563d2f5393_unicorn-60774.exe'
2025-07-02 12:29:03,696 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/8f82eb4f3e6c230e_unicorn-1028.exe'
2025-07-02 12:29:03,699 [cuckoo.core.resultserver] DEBUG: Task #6631181: File upload for 'files/9c416a7918506357_unicorn-58629.exe'
2025-07-02 12:29:03,703 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,706 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,709 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479334
2025-07-02 12:29:03,716 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479331
2025-07-02 12:29:03,719 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:03,722 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479332
2025-07-02 12:29:03,724 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479333
2025-07-02 12:29:03,728 [cuckoo.core.resultserver] DEBUG: Task #6631181 uploaded file length: 479335
2025-07-02 12:29:04,062 [cuckoo.core.resultserver] DEBUG: Task #6631181 had connection reset for <Context for LOG>
2025-07-02 12:30:20,714 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.223 for task #6631181
2025-07-02 12:30:22,174 [cuckoo.core.scheduler] DEBUG: Released database task #6631181
2025-07-02 12:30:22,190 [cuckoo.core.scheduler] INFO: Task #6631181: analysis procedure completed

Signatures

Yara rule detected for file (1 event)
description (no description) rule SEH__vba
One or more processes crashed (50 out of 2383 events)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39742965
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39742965
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1633676
registers.edi: 6098832
registers.eax: 1633676
registers.ebp: 1633756
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39742965
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1633624
registers.edi: 6098832
registers.eax: 1633624
registers.ebp: 1633704
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39715189
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 39742965
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2002335914
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
7c6e20f1b08b5437_unicorn-47813+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: 7c6e20f1b08b5437_unicorn-47813+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: 7c6e20f1b08b5437_unicorn-47813.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 6098832
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 6098832
registers.esi: 6098832
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-1028+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: unicorn-1028+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: Unicorn-1028.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 4
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 4
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 3350088
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 3350088
registers.esi: 3350088
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-1028+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: unicorn-1028+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: Unicorn-1028.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 3350088
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 3350088
registers.esi: 3350088
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-1028+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 00 00 75 fb 68 f8 c2 42 00 68 e4 9a 42 00 ff 15
exception.symbol: unicorn-1028+0x2ae48
exception.instruction: add byte ptr [eax], al
exception.module: Unicorn-1028.exe
exception.exception_code: 0xc0000005
exception.offset: 175688
exception.address: 0x42ae48
registers.esp: 1636952
registers.edi: 1637180
registers.eax: 0
registers.ebp: 1637168
registers.edx: 8
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 8
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 3350088
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 3350088
registers.esi: 3350088
registers.ecx: 2
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-1028+0x297eb @ 0x4297eb
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75e762fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75e76d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75e777c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75e77bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: 18 10 40 00 c7 45 f0 00 00 00 00 9b 68 7e b0 42
exception.symbol: unicorn-1028+0x2b01e
exception.instruction: sbb byte ptr [eax], dl
exception.module: Unicorn-1028.exe
exception.exception_code: 0xc0000005
exception.offset: 176158
exception.address: 0x42b01e
registers.esp: 1636952
registers.edi: 1637135
registers.eax: 4095
registers.ebp: 1637168
registers.edx: 20
registers.ebx: 4370453
registers.esi: 4198912
registers.ecx: 0
1 0 0

__exception__

stacktrace:
EbGetHandleOfExecutingProject+0x22b3 rtcPackDate-0xba9 msvbvm60+0xd0dcf @ 0x72a10dcf
rtcDoEvents+0x131 __vbaError-0x626 msvbvm60+0xce228 @ 0x72a0e228

exception.instruction_r: c9 c2 10 00 cc cc cc cc cc 8b ff 55 8b ec 56 8b
exception.symbol: RaiseException+0x58 CloseHandle-0x9 kernelbase+0xc41f
exception.instruction: leave
exception.module: KERNELBASE.dll
exception.exception_code: 0xc000008f
exception.offset: 50207
exception.address: 0x7507c41f
registers.esp: 1634992
registers.edi: 3350088
registers.eax: 1634992
registers.ebp: 1635072
registers.edx: 0
registers.ebx: 3350088
registers.esi: 3350088
registers.ecx: 2
1 0 0
Foreign language identified in PE resource (1 event)
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000747c4 size 0x00000234
Creates executable files on the filesystem (50 out of 453 events)
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-29777.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-16018.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-21828.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-37028.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-29668.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-3029.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-20344.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27675.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-13910.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-55732.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-17715.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-12645.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-4756.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-42974.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-60576.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-7907.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-34348.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-41333.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-1750.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-20331.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-41678.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-4478.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-17708.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-19976.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-44253.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-41112.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-23595.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-54988.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-47067.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-45726.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-56293.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-5281.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-28653.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-65521.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-11865.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-45200.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-46535.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-42661.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-22205.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-24436.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-19660.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-7838.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-61362.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-60516.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-22316.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-61200.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-39865.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-30812.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-56089.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-32661.exe
Drops an executable to the user AppData folder (2 events)
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27036.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-38672.exe
Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) (1 event)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2820
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x003b0000
process_handle: 0xffffffff
1 0 0
The binary likely contains encrypted or compressed data indicative of a packer (2 events)
section {u'size_of_data': u'0x0002b000', u'virtual_address': u'0x00001000', u'entropy': 7.571279461069391, u'name': u'.text', u'virtual_size': u'0x0002a5c4'} entropy 7.57127946107 description A section with a high entropy has been found
entropy 0.370689655172 description Overall entropy of this PE file is high
File has been identified by 13 AntiVirus engine on IRMA as malicious (13 events)
G Data Antivirus (Windows) Virus: Generic.Dacic.94CCEEA9.A.3F016658 (Engine A), Win32.Trojan.PSE.1FY1FUT (Engine B)
Avast Core Security (Linux) Win32:MalwareX-gen [Wrm]
C4S ClamAV (Linux) Win.Packed.Generic-9967832-0
Trellix (Linux) GenericRXTC-TT
WithSecure (Linux) Trojan.TR/Crypt.XPACK.Gen
eScan Antivirus (Linux) Generic.Dacic.94CCEEA9.A.3F016658(DB)
ESET Security (Windows) a variant of Win32/VBClone.E trojan
Sophos Anti-Virus (Linux) Troj/VB-KCP
DrWeb Antivirus (Linux) Trojan.Siggen31.13685
ClamAV (Linux) Win.Packed.Generic-9967832-0
Bitdefender Antivirus (Linux) Generic.Dacic.94CCEEA9.A.3F016658
Kaspersky Standard (Windows) Trojan.Win32.VB.dosq
Emsisoft Commandline Scanner (Windows) Generic.Dacic.94CCEEA9.A.3F016658 (B)
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.