Hello, we noticed that you are using . For the best performance of this application, we recommend to use Chrome, Firefox or any browser that supports WebKit.
2025-08-12 22:15:34,015 [analyzer] DEBUG: Starting analyzer from: C:\tmppw5mq4
2025-08-12 22:15:34,015 [analyzer] DEBUG: Pipe server name: \??\PIPE\ShoBNxSylzZCWJCdyYT
2025-08-12 22:15:34,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\xLaCtZQKjDDcpRHHvLigGXe
2025-08-12 22:15:34,390 [analyzer] DEBUG: Started auxiliary module Curtain
2025-08-12 22:15:34,390 [analyzer] DEBUG: Started auxiliary module DbgView
2025-08-12 22:15:34,967 [analyzer] DEBUG: Started auxiliary module Disguise
2025-08-12 22:15:35,171 [analyzer] DEBUG: Loaded monitor into process with pid 504
2025-08-12 22:15:35,171 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-08-12 22:15:35,171 [analyzer] DEBUG: Started auxiliary module Human
2025-08-12 22:15:35,171 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-08-12 22:15:35,187 [analyzer] DEBUG: Started auxiliary module Reboot
2025-08-12 22:15:35,312 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-08-12 22:15:35,312 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-08-12 22:15:35,312 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-08-12 22:15:35,312 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-08-12 22:15:35,453 [lib.api.process] INFO: Successfully executed process from path 'C:\\Program Files\\Internet Explorer\\iexplore.exe' with arguments ['https://livelo-pontos-2025.bbpts.online/?16220924368931489507'] and pid 1016
2025-08-12 22:15:35,592 [analyzer] DEBUG: Loaded monitor into process with pid 1016
2025-08-12 22:15:37,108 [analyzer] DEBUG: Following legitimate IE11 process: "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1016 CREDAT:275457 /prefetch:2!
2025-08-12 22:15:37,203 [analyzer] INFO: Injected into process with pid 1296 and name u'iexplore.exe'
2025-08-12 22:15:37,296 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1296.
2025-08-12 22:15:37,467 [analyzer] INFO: Added new file to list with pid 1016 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{1A988587-77B9-11F0-84C4-7AD289924ED8}.dat
2025-08-12 22:15:37,500 [analyzer] DEBUG: Loaded monitor into process with pid 1296
2025-08-12 22:15:37,500 [analyzer] INFO: Added new file to list with pid 1016 and path C:\Users\Administrator\AppData\Local\Temp\~DFD92EB07E24352426.TMP
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-08-12 22:15:37,733 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-08-12 22:15:37,750 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-08-12 22:15:38,015 [analyzer] INFO: Added new file to list with pid 1016 and path C:\Users\Administrator\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1A988589-77B9-11F0-84C4-7AD289924ED8}.dat
2025-08-12 22:15:38,030 [analyzer] INFO: Added new file to list with pid 1016 and path C:\Users\Administrator\AppData\Local\Temp\~DF0BF8BDFCB69DFB03.TMP
2025-08-12 22:15:38,140 [analyzer] DEBUG: Error resolving function mshtml!CDocument_write through our custom callback.
2025-08-12 22:15:38,140 [analyzer] DEBUG: Error resolving function mshtml!CElement_put_innerHTML through our custom callback.
2025-08-12 22:15:38,140 [analyzer] DEBUG: Error resolving function mshtml!CHyperlink_SetUrlComponent through our custom callback.
2025-08-12 22:15:38,140 [analyzer] DEBUG: Error resolving function mshtml!CIFrameElement_CreateElement through our custom callback.
2025-08-12 22:15:38,140 [analyzer] DEBUG: Error resolving function mshtml!CImgElement_put_src through our custom callback.
2025-08-12 22:15:38,155 [analyzer] DEBUG: Error resolving function mshtml!CScriptElement_put_src through our custom callback.
2025-08-12 22:15:38,155 [analyzer] DEBUG: Error resolving function mshtml!CWindow_AddTimeoutCode through our custom callback.
2025-08-12 22:15:38,155 [analyzer] INFO: Added new file to list with pid 1296 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M079LJW0\dnserror[1]
2025-08-12 22:15:38,203 [analyzer] INFO: Added new file to list with pid 1296 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L2PUX0TB\NewErrorPageTemplate[1]
2025-08-12 22:15:38,217 [analyzer] INFO: Added new file to list with pid 1296 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L1714XFE\errorPageStrings[1]
2025-08-12 22:15:38,233 [analyzer] INFO: Added new file to list with pid 1296 and path C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M079LJW0\httpErrorPagesScripts[1]
2025-08-12 21:16:49,719 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-08-12 21:16:49,907 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 1016.
2025-08-12 21:16:50,000 [lib.api.process] ERROR: Failed to dump memory of 32-bit process with pid 1296.
2025-08-12 21:16:50,298 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-08-12 21:16:50,298 [lib.api.process] INFO: Successfully terminated process with pid 1016.
2025-08-12 21:16:50,298 [lib.api.process] INFO: Successfully terminated process with pid 1296.
2025-08-12 21:16:50,298 [analyzer] INFO: Error dumping file from path "c:\users\administrator\appdata\local\temp\~dfd92eb07e24352426.tmp": [Errno 13] Permission denied: u'c:\\users\\administrator\\appdata\\local\\temp\\~dfd92eb07e24352426.tmp'
2025-08-12 21:16:50,359 [analyzer] WARNING: File at path u'c:\\users\\administrator\\appdata\\local\\temp\\~df0bf8bdfcb69dfb03.tmp' does not exist, skip.
2025-08-12 21:16:50,359 [analyzer] INFO: Analysis completed.