Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-04-10 13:22:28,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpd0os1j
2025-04-10 13:22:28,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\zTyhulrANbdAtXkcLcXAi
2025-04-10 13:22:28,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\vUtFotZAluJINUfEYoLJHaaWWU
2025-04-10 13:22:28,015 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-04-10 13:22:28,030 [analyzer] INFO: Automatically selected analysis package "ie"
2025-04-10 13:22:28,265 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-10 13:22:28,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-10 13:22:28,780 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-10 13:22:28,983 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-04-10 13:22:28,983 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-10 13:22:28,983 [analyzer] DEBUG: Started auxiliary module Human
2025-04-10 13:22:28,983 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-10 13:22:28,983 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-10 13:22:29,062 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-10 13:22:29,062 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-10 13:22:29,078 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-10 13:22:29,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-10 13:22:29,078 [modules.packages.ie] INFO: Submitted file is missing extension, adding .html
2025-04-10 13:22:29,171 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments [u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\e32383d4f51d9820bfe57f81f6b6fb2eb72bc4583aa914a1dc4d6dcc32cb0950.html'] and pid 824
2025-04-10 13:22:29,328 [analyzer] DEBUG: Loaded monitor into process with pid 824
2025-04-10 13:22:30,953 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:824 CREDAT:275457 /prefetch:2!
2025-04-10 13:22:31,015 [analyzer] INFO: Injected into process with pid 1912 and name u'iexplore.exe'
2025-04-10 13:22:31,092 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1912.
2025-04-10 13:22:31,203 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{16151AE7-15FE-11F0-BF07-40DD39EC8A9F}.dat
2025-04-10 13:22:31,250 [analyzer] DEBUG: Loaded monitor into process with pid 1912
2025-04-10 13:22:31,250 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\~DF682DC5985D0157BB.TMP
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-10 13:22:31,453 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-10 13:22:31,467 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-10 13:22:31,733 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{16151AE9-15FE-11F0-BF07-40DD39EC8A9F}.dat
2025-04-10 13:22:31,750 [analyzer] INFO: Added new file to list with pid 824 and path C:\Users\Administrator\AppData\Local\Temp\~DF4E3FE70C699984FB.TMP
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-10 13:22:31,812 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-10 13:22:31,828 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-10 13:22:35,000 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-04-10 13:22:35,000 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-04-10 13:22:35,000 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Cab5E67.tmp
2025-04-10 13:22:35,015 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Tar5E68.tmp
2025-04-10 13:22:35,015 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Cab5E79.tmp
2025-04-10 13:22:35,030 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Tar5E7A.tmp
2025-04-10 13:22:35,155 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-04-10 13:22:35,171 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-04-10 13:22:35,171 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Cab5F17.tmp
2025-04-10 13:22:35,171 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Tar5F18.tmp
2025-04-10 13:22:35,203 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Cab5F29.tmp
2025-04-10 13:22:35,203 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Tar5F2A.tmp
2025-04-10 13:22:35,342 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-04-10 13:22:35,342 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-04-10 13:22:35,405 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-04-10 13:22:35,405 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-04-10 13:22:35,437 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Cab6025.tmp
2025-04-10 13:22:35,437 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Temp\Tar6026.tmp
2025-04-10 13:22:35,453 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q0RFWJU9\jquery.cookie.min[1].js
2025-04-10 13:22:37,342 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4A9377E7E528F7E56B69A81C500ABC24
2025-04-10 13:22:37,342 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4A9377E7E528F7E56B69A81C500ABC24
2025-04-10 13:22:37,390 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199
2025-04-10 13:22:37,390 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199
2025-04-10 13:22:37,500 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DA548C7E5915679F87E910D6581DEF1_DDA8EF9211240E7A0402740E2A773ED2
2025-04-10 13:22:37,500 [analyzer] INFO: Added new file to list with pid 1912 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DA548C7E5915679F87E910D6581DEF1_DDA8EF9211240E7A0402740E2A773ED2
2025-04-10 13:22:58,187 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-10 13:22:58,655 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-10 13:22:58,655 [lib.api.process] INFO: Successfully terminated process with pid 824.
2025-04-10 13:22:58,655 [lib.api.process] INFO: Successfully terminated process with pid 1912.
2025-04-10 13:22:58,687 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar6026.tmp' does not exist, skip.
2025-04-10 13:22:58,687 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5f18.tmp' does not exist, skip.
2025-04-10 13:22:58,703 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5e68.tmp' does not exist, skip.
2025-04-10 13:22:58,703 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df4e3fe70c699984fb.tmp' does not exist, skip.
2025-04-10 13:22:58,703 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df682dc5985d0157bb.tmp' does not exist, skip.
2025-04-10 13:22:58,717 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5e79.tmp' does not exist, skip.
2025-04-10 13:22:58,717 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab6025.tmp' does not exist, skip.
2025-04-10 13:22:58,733 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5e7a.tmp' does not exist, skip.
2025-04-10 13:22:58,733 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5f17.tmp' does not exist, skip.
2025-04-10 13:22:58,750 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5e67.tmp' does not exist, skip.
2025-04-10 13:22:58,750 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5f2a.tmp' does not exist, skip.
2025-04-10 13:22:58,765 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5f29.tmp' does not exist, skip.
2025-04-10 13:22:58,765 [analyzer] INFO: Analysis completed.