Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Sept. 6, 2021, 6:19 p.m. | Sept. 6, 2021, 6:21 p.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3016 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2112 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
200 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1348 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1204 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2356 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1868 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2200 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
808 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2668 -
wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs"
2856-
Oggnfkemtibcinconsoleapp16.exe "C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe"
2072-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2656 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2240 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2208 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2684 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2880 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2248 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1296 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3024 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1472 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
1444 -
wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\test22\AppData\Local\Temp\Ddmmvlnwvosotwcisp.vbs"
192-
Hsbvhggsqlrfmuvyptooonsoleapp5.exe "C:\Users\test22\AppData\Local\Temp\Hsbvhggsqlrfmuvyptooonsoleapp5.exe"
2552-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
2080 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3108 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3248 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3360 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3472 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3616 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3728 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3840 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
4064 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com
3228 -
Hsbvhggsqlrfmuvyptooonsoleapp5.exe C:\Users\test22\AppData\Local\Temp\Hsbvhggsqlrfmuvyptooonsoleapp5.exe
3324
-
-
-
Oggnfkemtibcinconsoleapp16.exe C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe
1908-
cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Windows\system32\timeout.exe 3 & del "Oggnfkemtibcinconsoleapp16.exe"
3488-
timeout.exe C:\Windows\system32\timeout.exe 3
3520
-
-
-
-
-
-
cmd.exe cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\ghjkl.exe"
3944-
timeout.exe timeout /T 10 /NOBREAK
4008
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1848
Name | Response | Post-Analysis Lookup |
---|---|---|
google.com | 172.217.175.78 | |
telete.in | 195.201.225.248 | |
mazooyaar.ac.ug | 185.215.113.77 | |
mazoyer.ac.ug | 185.215.113.77 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49215 195.201.225.248:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=telecut.in | be:a6:3d:e8:93:c3:13:0b:5f:1d:3a:f7:63:57:4c:39:0e:96:df:5e |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
file | C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://45.142.215.237/ | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/6177c830445f6d0494ffcd9e25a157ee4342b34a | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/6936a2712329bb51d12294e3b6891e6d95b1d2d6 | ||||||
suspicious_features | POST method with no referer header | suspicious_request | POST http://mazoyer.ac.ug/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/softokn3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/sqlite3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/freebl3.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/mozglue.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/msvcp140.dll | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header | suspicious_request | POST http://mazooyaar.ac.ug/nss3.dll | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://telete.in/brikitiki |
request | POST http://45.142.215.237/ |
request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/6177c830445f6d0494ffcd9e25a157ee4342b34a |
request | GET http://45.142.215.237//l/f/nxZPunsBPvGyIjkLqZcB/6936a2712329bb51d12294e3b6891e6d95b1d2d6 |
request | POST http://mazoyer.ac.ug/index.php |
request | POST http://mazooyaar.ac.ug/softokn3.dll |
request | POST http://mazooyaar.ac.ug/sqlite3.dll |
request | POST http://mazooyaar.ac.ug/freebl3.dll |
request | POST http://mazooyaar.ac.ug/mozglue.dll |
request | POST http://mazooyaar.ac.ug/msvcp140.dll |
request | POST http://mazooyaar.ac.ug/nss3.dll |
request | GET https://telete.in/brikitiki |
request | POST http://45.142.215.237/ |
request | POST http://mazoyer.ac.ug/index.php |
request | POST http://mazooyaar.ac.ug/softokn3.dll |
request | POST http://mazooyaar.ac.ug/sqlite3.dll |
request | POST http://mazooyaar.ac.ug/freebl3.dll |
request | POST http://mazooyaar.ac.ug/mozglue.dll |
request | POST http://mazooyaar.ac.ug/msvcp140.dll |
request | POST http://mazooyaar.ac.ug/nss3.dll |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbai |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_1 |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\4cb013792b196a35_0 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Login Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Crashpad\metadata |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma~RF3a15fe.TMP\Web Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Cookies |
file | C:\Users\test22\AppData\Local\Google\Chrome\Login Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\290dcccb-9986-4f16-98a9-c54df8312e93 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Cookies |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Web Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Cookies |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\databases |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\Login Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\b1152479bea6c46553d8c242ffa5edf2b0a050a7\290dcccb-9986-4f16-98a9-c54df8312e93\index-dir |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\chrome_shutdown_ms.txt |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma\Web Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Cookies |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Thumbnails\000003.log |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PnaclTranslationCache\Login Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma\Cookies |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Login Data |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing Channel IDs-journal\Web Data |
file | C:\Sandbox\test22\DefaultBox\user\current\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\vcruntime140.dll |
file | C:\ProgramData\softokn3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ldap60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\freebl3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy_InUse.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\libEGL.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\lgpllibs.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssdbm3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\nssdbm3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozMapi32.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\open.PNG.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Settings.ini.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Access 2007.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\Automation Examples.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Automation Reference.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시작프로그램.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Module Docs.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPlus.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Math Input Panel.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HttpWatch Professional Edition\HttpWatch Studio.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7\Python Manuals.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\테스트.txt.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office\Microsoft Office Publisher 2007.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\다운로드.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exit.png.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk |
cmdline | cmd.exe /C timeout /T 10 /NOBREAK > Nul & Del /f /q "C:\Users\test22\AppData\Local\Temp\ghjkl.exe" |
cmdline | "C:\Windows\system32\cmd.exe" /c C:\Windows\system32\timeout.exe 3 & del "Oggnfkemtibcinconsoleapp16.exe" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Test-Connection -ComputerName google.com |
cmdline | powershell Test-Connection -ComputerName google.com |
cmdline | C:\Windows\System32\cmd.exe /c C:\Windows\system32\timeout.exe 3 & del "Oggnfkemtibcinconsoleapp16.exe" |
file | C:\Users\test22\AppData\Local\Temp\Dewgkwlbhkrsncbybkhtfpkb.vbs |
file | C:\Users\test22\AppData\Local\Temp\Oggnfkemtibcinconsoleapp16.exe |
file | C:\Users\test22\AppData\Local\Temp\Ddmmvlnwvosotwcisp.vbs |
file | C:\Users\test22\AppData\Local\Temp\Hsbvhggsqlrfmuvyptooonsoleapp5.exe |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-locale-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\breakpadinjector.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\prldap60.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nss3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\nss3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\softokn3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\vcruntime140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\MapiProxy.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\IA2Marshal.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\mozglue.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-memory-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\msvcp140.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\nssdbm3.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\AccessibleHandler.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\qipcap.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\Hsbvhggsqlrfmuvyptooonsoleapp5.exe |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processthreads-l1-1-1.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-file-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\sqlite3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\freebl3.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\ucrtbase.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\libEGL.dll |
file | C:\Users\test22\AppData\Local\Temp\ghjkl.exe |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\E1070B8B\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\LocalLow\aD1rF3aM8r\nssckbi.dll |
wmi | Select * from Win32_PingStatus where ((Address='google.com') And TimeToLive=80 And BufferSize=32) |