Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-04-25 17:22:13,000 [analyzer] DEBUG: Starting analyzer from: C:\tmp2pjrvv
2025-04-25 17:22:13,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\RSjgxIFqpHfzQUIUXfbcGKsjJDMrlS
2025-04-25 17:22:13,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\elOhZOKBpfswkQnM
2025-04-25 17:22:13,265 [analyzer] DEBUG: Started auxiliary module Curtain
2025-04-25 17:22:13,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-04-25 17:22:13,640 [analyzer] DEBUG: Started auxiliary module Disguise
2025-04-25 17:22:13,842 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-04-25 17:22:13,842 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-04-25 17:22:13,842 [analyzer] DEBUG: Started auxiliary module Human
2025-04-25 17:22:13,842 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-04-25 17:22:13,842 [analyzer] DEBUG: Started auxiliary module Reboot
2025-04-25 17:22:13,937 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-04-25 17:22:13,937 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-04-25 17:22:13,937 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-04-25 17:22:13,953 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-04-25 17:22:14,046 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['http://phacmeptaus.net'] and pid 2624
2025-04-25 17:22:14,203 [analyzer] DEBUG: Loaded monitor into process with pid 2624
2025-04-25 17:22:15,655 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2624 CREDAT:275457 /prefetch:2!
2025-04-25 17:22:15,717 [analyzer] INFO: Injected into process with pid 2724 and name u'iexplore.exe'
2025-04-25 17:22:15,828 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2724.
2025-04-25 17:22:15,983 [analyzer] INFO: Added new file to list with pid 2624 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{1052B43D-21E9-11F0-A35E-266C951AE353}.dat
2025-04-25 17:22:16,030 [analyzer] DEBUG: Loaded monitor into process with pid 2724
2025-04-25 17:22:16,078 [analyzer] INFO: Added new file to list with pid 2624 and path C:\Users\Administrator\AppData\Local\Temp\~DFC8675658388C250F.TMP
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 17:22:16,250 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 17:22:16,265 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 17:22:16,265 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 17:22:16,562 [analyzer] INFO: Added new file to list with pid 2624 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1052B43F-21E9-11F0-A35E-266C951AE353}.dat
2025-04-25 17:22:16,578 [analyzer] INFO: Added new file to list with pid 2624 and path C:\Users\Administrator\AppData\Local\Temp\~DFDB87463448E5C481.TMP
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-04-25 17:22:16,733 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-04-25 17:22:17,312 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8BRLFGE\http_404[1]
2025-04-25 17:22:17,328 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZMCDBW\ErrorPageTemplate[1]
2025-04-25 17:22:17,342 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NDSW7K6T\errorPageStrings[1]
2025-04-25 17:22:17,358 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8BRLFGE\httpErrorPagesScripts[1]
2025-04-25 17:22:17,358 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZMCDBW\info_48[1]
2025-04-25 17:22:17,390 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W8RXYR6O\bullet[1]
2025-04-25 17:22:17,390 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NDSW7K6T\down[1]
2025-04-25 17:22:17,437 [analyzer] INFO: Added new file to list with pid 2724 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G8BRLFGE\background_gradient[1]
2025-04-25 16:23:05,063 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-04-25 16:23:05,266 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2624.
2025-04-25 16:23:05,377 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 2724.
2025-04-25 16:23:05,641 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-04-25 16:23:05,641 [lib.api.process] INFO: Successfully terminated process with pid 2624.
2025-04-25 16:23:05,641 [lib.api.process] INFO: Successfully terminated process with pid 2724.
2025-04-25 16:23:05,720 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfdb87463448e5c481.tmp' does not exist, skip.
2025-04-25 16:23:05,720 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfc8675658388c250f.tmp' does not exist, skip.
2025-04-25 16:23:05,736 [analyzer] INFO: Analysis completed.