Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-06-15 10:00:43,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpt1gcja
2025-06-15 10:00:43,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\zEXbfFLFeStOfXyjRNp
2025-06-15 10:00:43,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\OwhmIwLuTBYotVnsDztl
2025-06-15 10:00:43,250 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-15 10:00:43,265 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-15 10:00:43,640 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-15 10:00:43,828 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-15 10:00:43,828 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-15 10:00:43,828 [analyzer] DEBUG: Started auxiliary module Human
2025-06-15 10:00:43,828 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-15 10:00:43,828 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-15 10:00:43,890 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-15 10:00:43,890 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-15 10:00:43,890 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-15 10:00:43,890 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-15 10:00:43,983 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://t.me/+zz0192lskaaa'] and pid 848
2025-06-15 10:00:44,140 [analyzer] DEBUG: Loaded monitor into process with pid 848
2025-06-15 10:00:45,453 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:848 CREDAT:275457 /prefetch:2!
2025-06-15 10:00:45,530 [analyzer] INFO: Injected into process with pid 1088 and name u'iexplore.exe'
2025-06-15 10:00:45,625 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1088.
2025-06-15 10:00:45,717 [analyzer] INFO: Added new file to list with pid 848 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D60E0AC7-49BE-11F0-8DEB-442FBD7DD98F}.dat
2025-06-15 10:00:45,780 [analyzer] INFO: Added new file to list with pid 848 and path C:\Users\Administrator\AppData\Local\Temp\~DF88EB6BE5B8BF7590.TMP
2025-06-15 10:00:45,796 [analyzer] DEBUG: Loaded monitor into process with pid 1088
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-06-15 10:00:45,983 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-06-15 10:00:46,000 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-06-15 10:00:46,217 [analyzer] INFO: Added new file to list with pid 848 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D60E0AC9-49BE-11F0-8DEB-442FBD7DD98F}.dat
2025-06-15 10:00:46,233 [analyzer] INFO: Added new file to list with pid 848 and path C:\Users\Administrator\AppData\Local\Temp\~DF682B3E7C86AC1850.TMP
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-06-15 10:00:46,608 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-06-15 10:00:46,608 [analyzer] INFO: Added new file to list with pid 1088 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0DSHQ0EW\dnserror[1]
2025-06-15 10:00:46,655 [analyzer] INFO: Added new file to list with pid 1088 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9P1H5NSK\NewErrorPageTemplate[1]
2025-06-15 10:00:46,655 [analyzer] INFO: Added new file to list with pid 1088 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KGRHG6BR\errorPageStrings[1]
2025-06-15 10:00:46,671 [analyzer] INFO: Added new file to list with pid 1088 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0DSHQ0EW\httpErrorPagesScripts[1]
2025-06-15 09:01:38,936 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-15 09:01:39,138 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 848.
2025-06-15 09:01:39,249 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1088.
2025-06-15 09:01:39,513 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-15 09:01:39,513 [lib.api.process] INFO: Successfully terminated process with pid 848.
2025-06-15 09:01:39,513 [lib.api.process] INFO: Successfully terminated process with pid 1088.
2025-06-15 09:01:39,529 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~df88eb6be5b8bf7590.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~df88eb6be5b8bf7590.tmp'
2025-06-15 09:01:39,545 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df682b3e7c86ac1850.tmp' does not exist, skip.
2025-06-15 09:01:39,561 [analyzer] INFO: Analysis completed.