Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-11-08 12:44:22,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpwwr_kc
2025-11-08 12:44:22,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\tAzoYYyesIFEadySie
2025-11-08 12:44:22,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\EBRDsPnphGqwKBuEAKFyZkeBIt
2025-11-08 12:44:22,312 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-08 12:44:22,312 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-08 12:44:22,842 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-08 12:44:23,108 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-11-08 12:44:23,108 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-08 12:44:23,108 [analyzer] DEBUG: Started auxiliary module Human
2025-11-08 12:44:23,108 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-08 12:44:23,108 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-08 12:44:23,187 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-08 12:44:23,187 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-08 12:44:23,187 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-08 12:44:23,187 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-08 12:44:23,358 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\9af0a7078db1596238683e4bb81599984533c07c159fe8163b0f101098acee4b.exe' with arguments '' and pid 2664
2025-11-08 12:44:23,592 [analyzer] DEBUG: Loaded monitor into process with pid 2664
2025-11-08 12:44:23,921 [analyzer] INFO: Added new file to list with pid 2664 and path C:\Users\Administrator\AppData\Local\Temp\9af0a7078db1596238683e4bb81599984533c07c159fe8163b0f101098acee4b.exe
2025-11-08 12:44:25,217 [analyzer] INFO: Injected into process with pid 2796 and name ''
2025-11-08 12:44:25,358 [analyzer] INFO: Process with pid 2664 has terminated
2025-11-08 12:44:25,390 [analyzer] DEBUG: Loaded monitor into process with pid 2796
2025-11-08 12:44:31,062 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 12:44:31,078 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 12:44:31,092 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Cab703D.tmp
2025-11-08 12:44:31,125 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Tar703E.tmp
2025-11-08 12:44:31,296 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-11-08 12:44:31,312 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-11-08 12:44:31,328 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Cab712A.tmp
2025-11-08 12:44:31,342 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Tar712B.tmp
2025-11-08 12:44:31,530 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 12:44:31,546 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 12:44:31,608 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 12:44:31,625 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 12:44:52,358 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-08 12:44:52,765 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-08 12:44:52,765 [lib.api.process] INFO: Successfully terminated process with pid 2796.
2025-11-08 12:44:52,828 [analyzer] INFO: Analysis completed.