Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-04-25 15:12:43,000 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc
2025-04-25 15:12:43,000 [analyzer] DEBUG: Pipe server name: \??\PIPE\NcmYolfhkArnPRszBujRAPTuiN
2025-04-25 15:12:43,000 [analyzer] DEBUG: Log pipe server name: \??\PIPE\mdzRouWphJFfYCogTbTNHGEkzPNo
2025-04-25 15:12:43,296 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-25 15:12:43,296 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-25 15:12:43,717 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-25 15:12:43,921 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-04-25 15:12:43,921 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-25 15:12:43,921 [analyzer] DEBUG: Started auxiliary module Human
2025-04-25 15:12:43,921 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-25 15:12:43,921 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-25 15:12:44,062 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-25 15:12:44,078 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-25 15:12:44,078 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-25 15:12:44,078 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-25 15:12:44,187 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://dkund.cfd/login/'] and pid 2488
2025-04-25 15:12:44,342 [analyzer] DEBUG: Loaded monitor into process with pid 2488
2025-04-25 15:12:45,733 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2488 CREDAT:275457 /prefetch:2!
2025-04-25 15:12:45,828 [analyzer] INFO: Injected into process with pid 396 and name u'iexplore.exe'
2025-04-25 15:12:45,937 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 396.
2025-04-25 15:12:46,078 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{F922A2C1-21D6-11F0-8B4F-C22250012F6A}.dat
2025-04-25 15:12:46,125 [analyzer] DEBUG: Loaded monitor into process with pid 396
2025-04-25 15:12:46,155 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Users\Administrator\AppData\Local\Temp\~DF643D89CB6CC5AAAF.TMP
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 15:12:46,358 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 15:12:46,375 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 15:12:46,375 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 15:12:46,375 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 15:12:46,375 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 15:12:46,375 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 15:12:46,390 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 15:12:46,390 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 15:12:46,655 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F922A2C3-21D6-11F0-8B4F-C22250012F6A}.dat
2025-04-25 15:12:46,687 [analyzer] INFO: Added new file to list with pid 2488 and path C:\Users\Administrator\AppData\Local\Temp\~DFE4EB335125CCF707.TMP
2025-04-25 15:12:47,296 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 15:12:47,296 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 15:12:47,296 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 15:12:47,296 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 15:12:47,312 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 15:12:47,312 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 15:12:47,312 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 15:12:47,312 [analyzer] INFO: Added new file to list with pid 396 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LEUFZ3L5\dnserror[1]
2025-04-25 15:12:47,342 [analyzer] INFO: Added new file to list with pid 396 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LNV4IY7C\NewErrorPageTemplate[1]
2025-04-25 15:12:47,358 [analyzer] INFO: Added new file to list with pid 396 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HWFTW34D\errorPageStrings[1]
2025-04-25 15:12:47,375 [analyzer] INFO: Added new file to list with pid 396 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M4GNMJ8V\httpErrorPagesScripts[1]
2025-04-25 14:13:32,825 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-25 14:13:33,028 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2488.
2025-04-25 14:13:33,121 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 396.
2025-04-25 14:13:33,387 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-25 14:13:33,387 [lib.api.process] INFO: Successfully terminated process with pid 2488.
2025-04-25 14:13:33,387 [lib.api.process] INFO: Successfully terminated process with pid 396.
2025-04-25 14:13:33,403 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfe4eb335125ccf707.tmp' does not exist, skip.
2025-04-25 14:13:33,418 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df643d89cb6cc5aaaf.tmp' does not exist, skip.
2025-04-25 14:13:33,434 [analyzer] INFO: Analysis completed.