Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-11-08 19:04:59,015 [analyzer] DEBUG: Starting analyzer from: C:\tmpdrdvpd
2025-11-08 19:04:59,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\eqNmRopqgLSSnKKElo
2025-11-08 19:04:59,015 [analyzer] DEBUG: Log pipe server name: \??\PIPE\JJEzSKpfXblvdEsPhMPtzSFuxQYIqqf
2025-11-08 19:04:59,280 [analyzer] DEBUG: Started auxiliary module Curtain
2025-11-08 19:04:59,280 [analyzer] DEBUG: Started auxiliary module DbgView
2025-11-08 19:05:00,000 [analyzer] DEBUG: Started auxiliary module Disguise
2025-11-08 19:05:00,250 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-11-08 19:05:00,250 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-11-08 19:05:00,250 [analyzer] DEBUG: Started auxiliary module Human
2025-11-08 19:05:00,250 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-11-08 19:05:00,250 [analyzer] DEBUG: Started auxiliary module Reboot
2025-11-08 19:05:00,342 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-11-08 19:05:00,342 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-11-08 19:05:00,342 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-11-08 19:05:00,342 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-11-08 19:05:00,453 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['http://o2o.to/i/tKrczf'] and pid 2816
2025-11-08 19:05:00,592 [analyzer] DEBUG: Loaded monitor into process with pid 2816
2025-11-08 19:05:01,953 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2816 CREDAT:275457 /prefetch:2!
2025-11-08 19:05:02,030 [analyzer] INFO: Injected into process with pid 320 and name u'iexplore.exe'
2025-11-08 19:05:02,108 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 320.
2025-11-08 19:05:02,250 [analyzer] INFO: Added new file to list with pid 2816 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{70EA03AD-BCCD-11F0-A9D1-30E4028CEEC5}.dat
2025-11-08 19:05:02,280 [analyzer] DEBUG: Loaded monitor into process with pid 320
2025-11-08 19:05:02,328 [analyzer] INFO: Added new file to list with pid 2816 and path C:\Users\Administrator\AppData\Local\Temp\~DFB6191E428692DBFC.TMP
2025-11-08 19:05:02,562 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:05:02,562 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:05:02,562 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:05:02,578 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:05:02,953 [analyzer] INFO: Added new file to list with pid 2816 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{70EA03AF-BCCD-11F0-A9D1-30E4028CEEC5}.dat
2025-11-08 19:05:02,983 [analyzer] INFO: Added new file to list with pid 2816 and path C:\Users\Administrator\AppData\Local\Temp\~DF651CC441F47C7D8F.TMP
2025-11-08 19:05:06,062 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 19:05:06,062 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\14232B434CF29D4C4FB335A86D7FFFE3
2025-11-08 19:05:06,062 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Cab5E1E.tmp
2025-11-08 19:05:06,078 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Tar5E1F.tmp
2025-11-08 19:05:06,217 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2025-11-08 19:05:06,217 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2025-11-08 19:05:06,233 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Cab5EBC.tmp
2025-11-08 19:05:06,233 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Tar5EBD.tmp
2025-11-08 19:05:06,375 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 19:05:06,375 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12
2025-11-08 19:05:06,421 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 19:05:06,421 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B46811C17859FFB409CF0E904A4AA8F8
2025-11-08 19:05:06,453 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Cab5FA9.tmp
2025-11-08 19:05:06,453 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Temp\Tar5FAA.tmp
2025-11-08 19:05:06,967 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\expired[1].htm
2025-11-08 19:05:06,967 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-11-08 19:05:06,967 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-11-08 19:05:06,967 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-11-08 19:05:06,967 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-11-08 19:05:06,983 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-11-08 19:05:06,983 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-11-08 19:05:06,983 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-11-08 19:05:07,140 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\vcd15cbe7772f49c399c6a5babf22c1241717689176015[1].js
2025-11-08 19:05:07,250 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\05DDC6AA91765AACACDB0A5F96DF8199
2025-11-08 19:05:07,250 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199
2025-11-08 19:05:07,342 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6DA548C7E5915679F87E910D6581DEF1_28A7AF702BEDBF8068D1A5B6E97195AF
2025-11-08 19:05:07,342 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6DA548C7E5915679F87E910D6581DEF1_28A7AF702BEDBF8068D1A5B6E97195AF
2025-11-08 19:05:07,562 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B3513D73A177A2707D910183759B389B_9201D057ABE60C9F67AAD1C1B9A101F0
2025-11-08 19:05:07,578 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B3513D73A177A2707D910183759B389B_9201D057ABE60C9F67AAD1C1B9A101F0
2025-11-08 19:05:07,592 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\memSYaGs126MiZpBA-UvWbX2vVnXBbObj2OVZyOOSr4dVJWUgsjZ0C4k[1].woff
2025-11-08 19:05:07,608 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NNU644SE\memSYaGs126MiZpBA-UvWbX2vVnXBbObj2OVZyOOSr4dVJWUgsgH1y4k[1].woff
2025-11-08 19:05:07,828 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\favicon[2].ico
2025-11-08 19:05:07,875 [analyzer] INFO: Added new file to list with pid 320 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\imagestore\x1a2xer\imagestore.dat
2025-11-08 19:05:29,453 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-11-08 19:05:29,687 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 2816.
2025-11-08 19:05:29,828 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 320.
2025-11-08 19:05:30,233 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-11-08 19:05:30,233 [lib.api.process] INFO: Successfully terminated process with pid 2816.
2025-11-08 19:05:30,233 [lib.api.process] INFO: Successfully terminated process with pid 320.
2025-11-08 19:05:30,233 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5e1e.tmp' does not exist, skip.
2025-11-08 19:05:30,312 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~dfb6191e428692dbfc.tmp' does not exist, skip.
2025-11-08 19:05:30,312 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5ebc.tmp' does not exist, skip.
2025-11-08 19:05:30,328 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5e1f.tmp' does not exist, skip.
2025-11-08 19:05:30,328 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5ebd.tmp' does not exist, skip.
2025-11-08 19:05:30,328 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df651cc441f47c7d8f.tmp' does not exist, skip.
2025-11-08 19:05:30,483 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\tar5faa.tmp' does not exist, skip.
2025-11-08 19:05:30,500 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\cab5fa9.tmp' does not exist, skip.
2025-11-08 19:05:30,515 [analyzer] INFO: Analysis completed.
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GIRKR6QC\vcd15cbe7772f49c399c6a5babf22c1241717689176015[1].js