Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Jan. 23, 2024, 7:55 a.m. | Jan. 23, 2024, 7:57 a.m. |
-
-
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST
2444 -
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST
2552 -
8CEyWgPtgDj3ygdsYA34.exe "C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8CEyWgPtgDj3ygdsYA34.exe"
2724-
-
iexplore.exe "C:\Program Files (x86)\Internet Explorer\iexplore.exe" SCODEF:2776 CREDAT:145409
2856
-
-
-
n6P8X5rop5bCHCDpw23f.exe "C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\n6P8X5rop5bCHCDpw23f.exe"
2100-
-
schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN explorhe.exe /TR "C:\Users\test22\AppData\Local\Temp\d887ceb89d\explorhe.exe" /F
2112 -
-
-
-
-
chcp.com chcp 1251
596 -
schtasks.exe schtasks /create /tn "MalayamaraUpdate" /tr "'C:\Users\test22\AppData\Local\Temp\Updater.exe'" /sc minute /mo 30 /F
3108
-
-
-
nsz9DA0.tmp C:\Users\test22\AppData\Local\Temp\nsz9DA0.tmp
3376
-
-
toolspub1.exe "C:\Users\test22\AppData\Local\Temp\toolspub1.exe"
3028 -
rty25.exe "C:\Users\test22\AppData\Local\Temp\rty25.exe"
2668 -
31839b57a4f11171d6abc8bbc4451ee4.exe "C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe"
2208
-
-
rundll32.exe "C:\Windows\System32\rundll32.exe" C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll, Main
3160 -
SetupPowerGREPDemo.exe "C:\Users\test22\AppData\Local\Temp\1000495001\SetupPowerGREPDemo.exe"
3260
-
-
-
Z2A_k3kHrLyUiJQeXEs0.exe "C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\Z2A_k3kHrLyUiJQeXEs0.exe"
2672 -
8G51dyVKnnvS40g1JD2e.exe "C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8G51dyVKnnvS40g1JD2e.exe"
2796 -
KdWG1WnjbLO0ejuSam0V.exe "C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\KdWG1WnjbLO0ejuSam0V.exe"
3024
-
-
explorer.exe C:\Windows\Explorer.EXE
1236
IP Address | Status | Action |
---|---|---|
104.26.4.15 | Active | Moloch |
109.107.182.3 | Active | Moloch |
117.18.232.200 | Active | Moloch |
142.251.220.68 | Active | Moloch |
154.92.15.189 | Active | Moloch |
164.124.101.2 | Active | Moloch |
173.194.174.84 | Active | Moloch |
185.172.128.109 | Active | Moloch |
185.172.128.19 | Active | Moloch |
185.172.128.53 | Active | Moloch |
185.172.128.90 | Active | Moloch |
185.215.113.68 | Active | Moloch |
193.233.132.62 | Active | Moloch |
216.58.200.227 | Active | Moloch |
34.117.186.192 | Active | Moloch |
61.111.58.35 | Active | Moloch |
87.251.77.166 | Active | Moloch |
94.177.48.37 | Active | Moloch |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49168 104.26.4.15:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 03:f8:79:dd:26:16:32:12:a4:33:99:34:af:f7:33:32:d5:e0:aa:e5 |
TLSv1 192.168.56.103:49185 173.194.174.84:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=accounts.google.com | e1:91:9a:16:6f:2f:49:fb:1c:f6:d7:db:dd:f0:e2:b0:9f:34:cc:e4 |
TLSv1 192.168.56.103:49189 216.58.200.227:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.gstatic.com | 6f:8c:8c:6f:06:bf:0d:24:7e:8d:3d:09:0d:07:26:df:c3:6e:47:c0 |
TLSv1 192.168.56.103:49188 216.58.200.227:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=*.gstatic.com | 6f:8c:8c:6f:06:bf:0d:24:7e:8d:3d:09:0d:07:26:df:c3:6e:47:c0 |
TLSv1 192.168.56.103:49199 142.251.220.68:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=www.google.com | cf:73:8c:78:50:35:aa:62:03:1d:34:01:0d:0e:90:a3:9a:5f:0d:d9 |
TLSv1 192.168.56.103:49198 142.251.220.68:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=www.google.com | cf:73:8c:78:50:35:aa:62:03:1d:34:01:0d:0e:90:a3:9a:5f:0d:d9 |
TLSv1 192.168.56.103:49186 173.194.174.84:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1C3 | CN=accounts.google.com | e1:91:9a:16:6f:2f:49:fb:1c:f6:d7:db:dd:f0:e2:b0:9f:34:cc:e4 |
TLSv1 192.168.56.103:49217 154.92.15.189:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=i.alie3ksgaa.com | e3:88:72:04:24:5c:12:17:a4:e2:c1:d9:33:f0:d9:60:91:71:d3:dc |
TLSv1 192.168.56.103:49222 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49228 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49229 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49230 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49231 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49232 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49233 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49234 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49236 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49237 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49242 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49245 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49246 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49244 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49239 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49241 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49247 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49248 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49253 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49238 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49251 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49255 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49257 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49262 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49243 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49552 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49642 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49648 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49323 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49340 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49645 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49650 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49263 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49470 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49647 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49653 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49639 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49655 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49661 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49646 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49644 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49663 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49649 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49652 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49651 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49656 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49659 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49657 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49660 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49662 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49667 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49668 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49674 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49676 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49684 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49681 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49691 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49673 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49692 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49671 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49677 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49669 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49675 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49670 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49678 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49672 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49685 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49679 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49683 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49686 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49688 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49680 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49689 94.177.48.37:443 |
C=US, O=Let's Encrypt, CN=R3 | CN=fleefight.it | 91:68:1d:27:8a:cf:73:d8:08:f0:ef:b4:c6:fe:7b:6c:17:be:10:d7 |
TLSv1 192.168.56.103:49687 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49690 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49693 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49694 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49695 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49696 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49697 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49225 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49250 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49261 104.26.4.15:443 |
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 | C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com | 03:f8:79:dd:26:16:32:12:a4:33:99:34:af:f7:33:32:d5:e0:aa:e5 |
TLSv1 192.168.56.103:49641 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49643 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49654 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49658 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49664 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49666 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49682 154.92.15.189:443 |
None | None | None |
TLSv1 192.168.56.103:49698 154.92.15.189:443 |
None | None | None |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
section |
suspicious_features | Connection to IP address | suspicious_request | HEAD http://109.107.182.3/cost/go.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://109.107.182.3/cost/go.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | HEAD http://185.215.113.68/mine/amer.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://185.215.113.68/mine/amer.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | HEAD http://109.107.182.3/cost/nika.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://109.107.182.3/cost/nika.exe | ||||||
suspicious_features | POST method with no referer header, POST method with no useragent header, Connection to IP address | suspicious_request | POST http://185.215.113.68/theme/index.php | ||||||
suspicious_features | Connection to IP address | suspicious_request | HEAD http://109.107.182.3/cost/vimu.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://109.107.182.3/cost/vimu.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.172.128.19/latestrocki.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | HEAD http://109.107.182.3/cost/networ.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://109.107.182.3/cost/networ.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://87.251.77.166/SetupPowerGREPDemo.exe | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.68/theme/Plugins/cred64.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://185.172.128.90/cpa/ping.php?substr=seven&s=ab | ||||||
suspicious_features | GET method with no useragent header, Connection to IP address | suspicious_request | GET http://185.215.113.68/theme/Plugins/clip64.dll | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://185.172.128.109/syncUpd.exe |
request | HEAD http://109.107.182.3/cost/go.exe |
request | GET http://109.107.182.3/cost/go.exe |
request | HEAD http://185.215.113.68/mine/amer.exe |
request | GET http://185.215.113.68/mine/amer.exe |
request | HEAD http://109.107.182.3/cost/nika.exe |
request | GET http://109.107.182.3/cost/nika.exe |
request | POST http://185.215.113.68/theme/index.php |
request | HEAD http://109.107.182.3/cost/vimu.exe |
request | GET http://109.107.182.3/cost/vimu.exe |
request | GET http://185.172.128.19/latestrocki.exe |
request | HEAD http://109.107.182.3/cost/networ.exe |
request | GET http://109.107.182.3/cost/networ.exe |
request | GET http://87.251.77.166/SetupPowerGREPDemo.exe |
request | GET http://185.215.113.68/theme/Plugins/cred64.dll |
request | GET http://185.172.128.90/cpa/ping.php?substr=seven&s=ab |
request | GET http://185.215.113.68/theme/Plugins/clip64.dll |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | GET http://185.172.128.109/syncUpd.exe |
request | GET http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml |
request | GET https://db-ip.com/demo/home.php?s=175.208.134.152 |
request | GET https://accounts.google.com/ |
request | GET https://accounts.google.com/ServiceLogin?passive=1209600&continue=https%3A%2F%2Faccounts.google.com%2F&followup=https%3A%2F%2Faccounts.google.com%2F |
request | GET https://accounts.google.com/InteractiveLogin?continue=https://accounts.google.com/&followup=https://accounts.google.com/&passive=1209600&ifkv=ASKXGp0prvDtaojbUs_fFiN9b9CD7hkEJ1nHDhTfd9vIUqM3YxyI4uMpGixUZhaFGRKzHsJvSPCU |
request | GET https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Faccounts.google.com%2F&followup=https%3A%2F%2Faccounts.google.com%2F&ifkv=ASKXGp19ppAsRv2o6lyozUloXtl2vtHTQ_Z5hQtp6-dWz_Yb_d5Sog8ygYecStquNLy1xgWdXfMz&passive=1209600&flowName=WebLiteSignIn&flowEntry=ServiceLogin&dsh=S-955853393%3A1705964159222861 |
request | GET https://accounts.google.com/_/bscframe |
request | GET https://ssl.gstatic.com/images/branding/googlelogo/2x/googlelogo_color_74x24dp.png |
request | GET https://accounts.google.com/favicon.ico |
request | GET https://www.google.com/favicon.ico |
request | GET https://accounts.google.com/generate_204?dNjB8g |
request | POST http://185.215.113.68/theme/index.php |
description | explorhe.exe tried to sleep 266 seconds, actually delayed analysis time by 266 seconds |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Local Extension Settings\cjmkndjhnagcfbpiemnkdpomccnjblmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Sync Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Local Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\Sync Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OnDeviceHeadSuggestModel\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbic\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SafetyTips\Sync Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Sync Extension Settings\aijcbedoijmgnlmjeegjaglmepbmpkpi\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ThirdPartyModuleList64\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffne\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FontLookupTableCache\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Sync Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Local Extension Settings\bgpipimickeadkjlklgciifhnalhdjhe\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Sync Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Local Extension Settings\epapihdplajcdnnkdeiahlgigofloibg\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Sync Extension Settings\mgffkfbidihjpoaomajlbgchddlicgpn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Sync Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdma\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflc\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\RecoveryImproved\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpi\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Sync Extension Settings\jnkelfanjkeadonecabehalmbgpfodjm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Local Extension Settings\gjagmgiddbbciopjhllkdnddhcglnemk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Sync Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\MEIPreload\Sync Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Sync Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\recovery\Sync Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Sync Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Sync Extension Settings\fhilaheimglignddkjgofkcbgekhenbh\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TLSDeprecationConfig\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcobl\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crowd Deny\Sync Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ZxcvbnData\Sync Extension Settings\kpfopkelmapcoipemfendmdcghnegimn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Sync Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Local Extension Settings\aijcbedoijmgnlmjeegjaglmepbmpkpi\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\TrustTokenKeyCommitments\Local Extension Settings\pdadjkfkgcafgbceimcpbkalnfnepbnk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\GrShaderCache\Local Extension Settings\gjagmgiddbbciopjhllkdnddhcglnemk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Sync Extension Settings\oeljdldpnmdbchonielidgobddffflal\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Sync Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Subresource Filter\Sync Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm\CURRENT |
domain | ipinfo.io |
file | C:\Users\test22\AppData\Roaming\006700e5a2ab05\cred64.dll |
file | C:\Users\test22\AppData\Roaming\Temp\Task.bat |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8CEyWgPtgDj3ygdsYA34.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\KdWG1WnjbLO0ejuSam0V.exe |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\nsl94D5.tmp\INetC.dll |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\n6P8X5rop5bCHCDpw23f.exe |
file | C:\Users\test22\AppData\Roaming\006700e5a2ab05\clip64.dll |
file | C:\Users\test22\AppData\Local\Temp\BroomSetup.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\Z2A_k3kHrLyUiJQeXEs0.exe |
file | C:\Users\test22\AppData\Local\Temp\1000493001\latestrocki.exe |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
file | C:\Users\test22\AppData\Local\Temp\1000495001\SetupPowerGREPDemo.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8G51dyVKnnvS40g1JD2e.exe |
cmdline | schtasks /create /tn "MalayamaraUpdate" /tr "'C:\Users\test22\AppData\Local\Temp\Updater.exe'" /sc minute /mo 30 /F |
cmdline | "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN explorhe.exe /TR "C:\Users\test22\AppData\Local\Temp\d887ceb89d\explorhe.exe" /F |
cmdline | SCHTASKS /Create /SC MINUTE /MO 1 /TN explorhe.exe /TR "C:\Users\test22\AppData\Local\Temp\d887ceb89d\explorhe.exe" /F |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 HR" /sc HOURLY /rl HIGHEST |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MPGPH131\MPGPH131.exe" /tn "MPGPH131 LG" /sc ONLOGON /rl HIGHEST |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8CEyWgPtgDj3ygdsYA34.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\Z2A_k3kHrLyUiJQeXEs0.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8G51dyVKnnvS40g1JD2e.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\KdWG1WnjbLO0ejuSam0V.exe |
file | C:\Users\test22\AppData\Local\Temp\d887ceb89d\explorhe.exe |
file | C:\Users\test22\AppData\Local\Temp\1000493001\latestrocki.exe |
file | C:\Users\test22\AppData\Local\Temp\1000495001\SetupPowerGREPDemo.exe |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\rty25.exe |
file | C:\Users\test22\AppData\Local\Temp\SandboxieInstall.exe |
file | C:\Users\test22\AppData\Local\Temp\toolspub1.exe |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYECVYBT\clip64[1].dll |
file | C:\Users\test22\AppData\Local\Temp\nsz9DA0.tmp |
file | C:\Users\test22\AppData\Local\Temp\1000493001\latestrocki.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\Z2A_k3kHrLyUiJQeXEs0.exe |
file | C:\Users\test22\AppData\Local\Temp\BroomSetup.exe |
file | C:\Users\test22\AppData\Local\Temp\202005191702_6d173b9549ce4fe1e5ada5ab9ce0bfff5d9569f19e7fa916db5c8d4f0dace63b_setup_nwc275a_demo.exe |
file | C:\Users\test22\AppData\Local\Temp\Setup00000994\OSETUPUI.DLL |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\KdWG1WnjbLO0ejuSam0V.exe |
file | C:\Users\test22\AppData\Local\Temp\Setup00000994\OSETUP.DLL |
file | C:\Users\test22\AppData\Local\Temp\face.exe |
file | C:\Users\test22\AppData\Local\Temp\Setup000023ac\OSETUP.DLL |
file | C:\Users\test22\AppData\Local\Temp\Setup000023ac\ose00000.exe |
file | C:\Users\test22\AppData\Local\Temp\Setup00000994\ose00000.exe |
file | C:\Users\test22\AppData\Local\Temp\nsl94D5.tmp\INetC.dll |
file | C:\Users\test22\AppData\Local\Temp\31839b57a4f11171d6abc8bbc4451ee4.exe |
file | C:\Users\test22\AppData\Local\Temp\d887ceb89d\explorhe.exe |
file | C:\Users\test22\AppData\Local\Temp\InstallSetup7.exe |
file | C:\Users\test22\AppData\Local\Temp\Setup000023ac\OSETUPUI.DLL |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8CEyWgPtgDj3ygdsYA34.exe |
file | C:\Users\test22\AppData\Local\Temp\jobA4F6U_tCj88G2a2\8G51dyVKnnvS40g1JD2e.exe |