File name:

2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer

Full analysis: https://app.any.run/tasks/8819bb71-65ce-44c8-84cb-e2a9cb888896
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: June 21, 2025, 18:45:35
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

41EDD1424A5AD3398102C7A451F57588

SHA1:

10037158ECA22F562E72B5454B7B40A60A7869C0

SHA256:

27E048D8A2C4558D8F2B3EF88C66FB2F68DCB0B957C1F90A86F4A1E9506B8984

SSDEEP:

6144:nzO8/AkuCCs4TEfQFv0tBjvmG26YZ1cl0tB7o:n7uCCFIIFvuBM1cl0tB7o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Potential Corporate Privacy Violation

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
    • Process requests binary or script from the Internet

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
    • Executable content was dropped or overwritten

      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
  • INFO

    • Reads the computer name

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • The sample compiled with english language support

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Reads the machine GUID from the registry

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Checks supported languages

      • 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe (PID: 3092)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Checks proxy server information

      • slui.exe (PID: 4032)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Creates files in the program directory

      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Reads CPU info

      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Reads the software policy settings

      • slui.exe (PID: 4032)
      • avast_free_antivirus_setup_online_x64.exe (PID: 5560)
      • Instup.exe (PID: 7072)
    • Reads Environment values

      • Instup.exe (PID: 7072)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | DOS Executable Generic (100)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:03 16:42:16+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.15
CodeSize: 128512
InitializedDataSize: 76800
UninitializedDataSize: -
EntryPoint: 0x10d0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.1.1252.0
ProductVersionNumber: 2.1.1252.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: AVAST Software
Edition: 1
FileDescription: Avast Antivirus Installer
FileVersion: 2.1.1252.0
InternalName: microstub
LegalCopyright: Copyright (c) 2019 AVAST Software
OriginalFileName: microstub.exe
ProductName: Avast MicroInstaller
ProductVersion: 2.1.1252.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
5
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe slui.exe avast_free_antivirus_setup_online_x64.exe instup.exe 2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2952"C:\Users\admin\Desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe" C:\Users\admin\Desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exeexplorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
MEDIUM
Description:
Avast Antivirus Installer
Exit code:
3221226540
Version:
2.1.1252.0
Modules
Images
c:\users\admin\desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3092"C:\Users\admin\Desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe" C:\Users\admin\Desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
explorer.exe
User:
admin
Company:
AVAST Software
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
2.1.1252.0
Modules
Images
c:\users\admin\desktop\2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4032C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5560"C:\WINDOWS\Temp\asw.9b99d012638fe22d\avast_free_antivirus_setup_online_x64.exe" /ga_clientid:592535d8-a5ca-4fce-af2d-480743257c19 /edat_dir:C:\WINDOWS\Temp\asw.9b99d012638fe22dC:\Windows\Temp\asw.9b99d012638fe22d\avast_free_antivirus_setup_online_x64.exe
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus
Version:
25.5.10141.0
Modules
Images
c:\windows\temp\asw.9b99d012638fe22d\avast_free_antivirus_setup_online_x64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\win32u.dll
c:\windows\system32\user32.dll
7072"C:\WINDOWS\Temp\asw.c3f347d8c74fd5de\instup.exe" /sfx:lite /sfxstorage:C:\WINDOWS\Temp\asw.c3f347d8c74fd5de /edition:1 /prod:ais /stub_context:32573215-2809-4004-a2bc-add2bf51bb21:11333856 /cookie:mmm_fhp_dlp_000_119_a /guid:6b79fbf6-0dc8-4d0b-8adc-d2fbb60b8d36 /ga_clientid:592535d8-a5ca-4fce-af2d-480743257c19 /ga_clientid:592535d8-a5ca-4fce-af2d-480743257c19 /edat_dir:C:\WINDOWS\Temp\asw.9b99d012638fe22dC:\Windows\Temp\asw.c3f347d8c74fd5de\Instup.exe
avast_free_antivirus_setup_online_x64.exe
User:
admin
Company:
Gen Digital Inc.
Integrity Level:
HIGH
Description:
Avast Antivirus Installer
Version:
25.5.10141.0
Modules
Images
c:\windows\temp\asw.c3f347d8c74fd5de\instup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
Total events
11 471
Read events
10 974
Write events
496
Delete events
1

Modification events

(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software
Operation:delete keyName:(default)
Value:
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Avast Software
Operation:writeName:SymbolicLinkValue
Value:
\Registry\MACHINE\SOFTWARE\Avast Software
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
0
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
7
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
14
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
21
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
28
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
35
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
42
(PID) Process:(5560) avast_free_antivirus_setup_online_x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AvastPersistentStorage
Operation:writeName:SfxInstProgress
Value:
50
Executable files
11
Suspicious files
13
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\servers.deftext
MD5:B6169F581D5DAB0C5509A9A2AF365CE3
SHA256:F2444033740B9E2B7007BC64F18AB9C688378A4F55D4A7D0FD2CADA5DE87D070
5560avast_free_antivirus_setup_online_x64.exeC:\ProgramData\Avast Software\Persistent Data\Avast\Logs\Setup.logtext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\part-prg_ais-19051812.vpxbinary
MD5:6CD3EF22DBD149AFA415F3315B880100
SHA256:1CCE746306CA14B791D27FB9D880ADA3D2C3B6B87B2ACB16F467678D50EB235F
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\prod-pgm.vpxbinary
MD5:BBBA9A0F3197BC138E02467AE5D56F2D
SHA256:1BE49EDB6D6941DC7BDFC62982E3197233D9A54F1F8D1A7D6E54FBCA4B66248F
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\Instup.exeexecutable
MD5:46E980A47E0C523C1931B5F7706AF8EC
SHA256:B097969CCA58F40B19708E9136A6B5F3C1E35AA0ADC04E9B696F7370936AD2A8
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\servers.def.vpxbinary
MD5:1C6D57F59D7CF90EAFFB379A66739BF2
SHA256:D5FA227EF6C4E1A8E2BC90673073F4D4E3D1C60D915498E9D171580D290916DE
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\cookie.bintext
MD5:04E09E288D861E312A7B23AA90EB02F2
SHA256:8C32C137AB8A7ABB59E815AC9812C2EADC4C6A7D97FEA6E9A4B0C05B7BF5DB25
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\uat.vpxbinary
MD5:F7A46A00704A18A98A2EE9D16478D07E
SHA256:85950C27E07F8DF15BCEB3F884278DCAFAFACFBFA3B905CFE17163A032EB0B12
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\part-setup_ais-19051812.vpxbinary
MD5:7ED64050C9460968454663C64AF94446
SHA256:1089225A5156010957E4C5C96AD4877155F03EF67937AFC657F79611F841055C
5560avast_free_antivirus_setup_online_x64.exeC:\Windows\Temp\asw.c3f347d8c74fd5de\HTMLayout.dllexecutable
MD5:44D194AF596DB664EF23297B4767FE57
SHA256:BFF8F1675975350330DF1D297EB38B1F3BF85CB08C8F0D4AA4680C3C5F3E4A77
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
60
DNS requests
107
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3092
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
POST
204
34.117.223.223:80
http://v7event.stats.avast.com/cgi-bin/iavsevents.cgi
unknown
whitelisted
1268
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
200
20.190.160.22:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
POST
200
40.126.32.133:443
https://login.live.com/ppsecure/deviceaddcredential.srf
unknown
text
16.7 Kb
whitelisted
1488
RUXIMICS.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
200
20.190.160.14:443
https://login.live.com/RST2.srf
unknown
xml
10.3 Kb
whitelisted
GET
304
4.245.163.56:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
3460
SIHClient.exe
GET
200
23.55.104.190:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
POST
200
20.190.160.14:443
https://login.live.com/RST2.srf
unknown
xml
11.0 Kb
whitelisted
3460
SIHClient.exe
GET
200
23.55.104.190:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1488
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3092
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
34.117.223.223:80
v7event.stats.avast.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
3092
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
142.250.185.238:80
www.google-analytics.com
GOOGLE
US
whitelisted
3092
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
23.48.23.6:80
iavs9x.u.avast.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1488
RUXIMICS.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.google-analytics.com
  • 142.250.185.238
whitelisted
iavs9x.u.avast.com
  • 23.48.23.6
  • 23.48.23.20
whitelisted
v7event.stats.avast.com
  • 34.117.223.223
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
  • 23.55.104.190
  • 23.55.104.172
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.248
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.23
  • 40.126.31.0
  • 40.126.31.129
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.131
  • 20.190.159.68
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted

Threats

PID
Process
Class
Message
3092
2025-06-21_41edd1424a5ad3398102c7a451f57588_amadey_black-basta_cobalt-strike_elex_luca-stealer.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:37.458] [notice ] [sfxinst ] [ 5560: 2664] [F7235D: 393] Registry link creation 'SOFTWARE\WOW6432Node\Avast Software' -> 'SOFTWARE\Avast Software' was successful.
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:37.458] [info ] [sfxinst ] [ 5560: 2664] [F7235D: 410] Running SFX 'C:\WINDOWS\Temp\asw.9b99d012638fe22d\avast_free_antivirus_setup_online_x64.exe'
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:37.661] [info ] [sfxinst ] [ 5560: 2664] [F7235D: 658] Moved extra data file 'ecoo.edat' to 'C:\WINDOWS\Temp\asw.c3f347d8c74fd5de\cookie.bin'.
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:38.505] [notice ] [burger_rep ] [ 5560: 6672] [2A6316: 64] The event '70.1' was successfully sent to burger: https://analytics.avcdn.net/v4/receive/json/70.
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:38.615] [info ] [sfxstats ] [ 5560: 7092] [738CF6: 149] Statistics sent successfully.
avast_free_antivirus_setup_online_x64.exe
[2025-06-21 18:47:38.942] [info ] [sfxinst ] [ 5560: 2664] [F7235D: 948] Starting installer/updater executable 'C:\WINDOWS\Temp\asw.c3f347d8c74fd5de\instup.exe'
Instup.exe
[2025-06-21 18:47:39.208] [info ] [ini_access ] [ 7072: 5528] [6ACBED: 185] first use of ini file C:\WINDOWS\Temp\asw.c3f347d8c74fd5de\servers.def
Instup.exe
[2025-06-21 18:47:39.208] [info ] [instup ] [ 7072: 5528] [4E073C:2674] OS: Windows 10 (10.0.19045) x64
Instup.exe
[2025-06-21 18:47:39.208] [info ] [instup ] [ 7072: 5528] [4E073C:2669] CPU: Intel(R) Core(TM) i5-6400 CPU @ 2.70GHz,4
Instup.exe
[2025-06-21 18:47:39.208] [info ] [shepsync ] [ 7072: 5528] [08F6CD: 95] Wait interval 60