Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-07-27 06:13:32,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpk4d6bl
2025-07-27 06:13:32,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\UcmdWEzCgUaNOLXYe
2025-07-27 06:13:32,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\XAHzdXpPBLtukVfx
2025-07-27 06:13:32,030 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-07-27 06:13:32,046 [analyzer] INFO: Automatically selected analysis package "exe"
2025-07-27 06:13:32,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-07-27 06:13:32,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-07-27 06:13:32,765 [analyzer] DEBUG: Started auxiliary module Disguise
2025-07-27 06:13:32,983 [analyzer] DEBUG: Loaded monitor into process with pid 512
2025-07-27 06:13:33,000 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-07-27 06:13:33,000 [analyzer] DEBUG: Started auxiliary module Human
2025-07-27 06:13:33,000 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-07-27 06:13:33,000 [analyzer] DEBUG: Started auxiliary module Reboot
2025-07-27 06:13:33,125 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-07-27 06:13:33,125 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-07-27 06:13:33,125 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-07-27 06:13:33,125 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-07-27 06:13:33,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\46814408d1951069_winhelp59.exe' with arguments '' and pid 1776
2025-07-27 06:13:33,546 [analyzer] DEBUG: Loaded monitor into process with pid 1776
2025-07-27 06:13:33,578 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Users\Administrator\AppData\Local\Temp\20397593.reg
2025-07-27 06:13:33,687 [analyzer] INFO: Injected into process with pid 788 and name u'regedit.exe'
2025-07-27 06:13:33,687 [analyzer] INFO: Added new file to list with pid 1776 and path C:\Windows\SysWOW64\WinHelp93.exe
2025-07-27 06:13:33,905 [analyzer] DEBUG: Loaded monitor into process with pid 788
2025-07-27 06:13:34,375 [analyzer] INFO: Process with pid 788 has terminated
2025-07-27 06:13:38,592 [analyzer] INFO: Injected into process with pid 1896 and name u'WinHelp93.exe'
2025-07-27 06:13:38,750 [analyzer] DEBUG: Loaded monitor into process with pid 1896
2025-07-27 06:13:38,858 [analyzer] INFO: Injected into process with pid 1308 and name u'svchost.exe'
2025-07-27 06:13:39,375 [analyzer] INFO: Process with pid 1776 has terminated
2025-07-27 06:13:40,375 [analyzer] INFO: Process with pid 1896 has terminated
2025-07-27 06:13:41,375 [analyzer] INFO: Process with pid 1308 has terminated
2025-07-27 06:13:41,375 [analyzer] INFO: Process list is empty, terminating analysis.
2025-07-27 06:13:42,608 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-07-27 06:13:42,625 [analyzer] INFO: Analysis completed.