Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.98.116.138 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 23.43.61.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.50.201.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.68.123.157 |
Source: sets.json.6.dr |
String found in binary or memory: https://abczdrowie.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://alice.tw |
Source: sets.json.6.dr |
String found in binary or memory: https://autobild.de |
Source: sets.json.6.dr |
String found in binary or memory: https://baomoi.com |
Source: sets.json.6.dr |
String found in binary or memory: https://bild.de |
Source: sets.json.6.dr |
String found in binary or memory: https://blackrock.com |
Source: sets.json.6.dr |
String found in binary or memory: https://blackrockadvisorelite.it |
Source: sets.json.6.dr |
String found in binary or memory: https://bluradio.com |
Source: sets.json.6.dr |
String found in binary or memory: https://bolasport.com |
Source: sets.json.6.dr |
String found in binary or memory: https://bonvivir.com |
Source: sets.json.6.dr |
String found in binary or memory: https://bumbox.com |
Source: sets.json.6.dr |
String found in binary or memory: https://businessinsider.com.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://cachematrix.com |
Source: sets.json.6.dr |
String found in binary or memory: https://cafemedia.com |
Source: sets.json.6.dr |
String found in binary or memory: https://caracoltv.com |
Source: sets.json.6.dr |
String found in binary or memory: https://carcostadvisor.be |
Source: sets.json.6.dr |
String found in binary or memory: https://carcostadvisor.com |
Source: sets.json.6.dr |
String found in binary or memory: https://carcostadvisor.fr |
Source: sets.json.6.dr |
String found in binary or memory: https://cardsayings.net |
Source: sets.json.6.dr |
String found in binary or memory: https://chennien.com |
Source: sets.json.6.dr |
String found in binary or memory: https://clarosports.com |
Source: sets.json.6.dr |
String found in binary or memory: https://clmbtech.com |
Source: sets.json.6.dr |
String found in binary or memory: https://clubelpais.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://cmxd.com.mx |
Source: sets.json.6.dr |
String found in binary or memory: https://commentcamarche.com |
Source: sets.json.6.dr |
String found in binary or memory: https://commentcamarche.net |
Source: sets.json.6.dr |
String found in binary or memory: https://computerbild.de |
Source: sets.json.6.dr |
String found in binary or memory: https://cookreactor.com |
Source: sets.json.6.dr |
String found in binary or memory: https://cricbuzz.com |
Source: sets.json.6.dr |
String found in binary or memory: https://desimartini.com |
Source: sets.json.6.dr |
String found in binary or memory: https://dewarmsteweek.be |
Source: sets.json.6.dr |
String found in binary or memory: https://economictimes.com |
Source: sets.json.6.dr |
String found in binary or memory: https://een.be |
Source: sets.json.6.dr |
String found in binary or memory: https://efront.com |
Source: sets.json.6.dr |
String found in binary or memory: https://eleconomista.net |
Source: sets.json.6.dr |
String found in binary or memory: https://elfinancierocr.com |
Source: sets.json.6.dr |
String found in binary or memory: https://elgrafico.com |
Source: sets.json.6.dr |
String found in binary or memory: https://ella.sv |
Source: sets.json.6.dr |
String found in binary or memory: https://elpais.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://elpais.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://etfacademy.it |
Source: sets.json.6.dr |
String found in binary or memory: https://eworkbookcloud.com |
Source: sets.json.6.dr |
String found in binary or memory: https://eworkbookrequest.com |
Source: sets.json.6.dr |
String found in binary or memory: https://fakt.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://finn.no |
Source: sets.json.6.dr |
String found in binary or memory: https://firstlook.biz |
Source: sets.json.6.dr |
String found in binary or memory: https://gallito.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://gettalkdesk.com |
Source: sets.json.6.dr |
String found in binary or memory: https://gliadomain.com |
Source: sets.json.6.dr |
String found in binary or memory: https://grid.id |
Source: sets.json.6.dr |
String found in binary or memory: https://gridgames.app |
Source: sets.json.6.dr |
String found in binary or memory: https://growthrx.in |
Source: sets.json.6.dr |
String found in binary or memory: https://grupolpg.sv |
Source: sets.json.6.dr |
String found in binary or memory: https://gujaratijagran.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hapara.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hc1.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hc1.global |
Source: sets.json.6.dr |
String found in binary or memory: https://hc1cas.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hc1cas.global |
Source: sets.json.6.dr |
String found in binary or memory: https://healthshots.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hearty.app |
Source: sets.json.6.dr |
String found in binary or memory: https://hearty.gift |
Source: sets.json.6.dr |
String found in binary or memory: https://hearty.me |
Source: sets.json.6.dr |
String found in binary or memory: https://heartymail.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hindustantimes.com |
Source: sets.json.6.dr |
String found in binary or memory: https://hj.rs |
Source: sets.json.6.dr |
String found in binary or memory: https://hjck.com |
Source: sets.json.6.dr |
String found in binary or memory: https://human-talk.org |
Source: sets.json.6.dr |
String found in binary or memory: https://idbs-cloud.com |
Source: sets.json.6.dr |
String found in binary or memory: https://idbs-dev.com |
Source: sets.json.6.dr |
String found in binary or memory: https://idbs-eworkbook.com |
Source: sets.json.6.dr |
String found in binary or memory: https://idbs-staging.com |
Source: sets.json.6.dr |
String found in binary or memory: https://indiatimes.com |
Source: sets.json.6.dr |
String found in binary or memory: https://iolam.it |
Source: sets.json.6.dr |
String found in binary or memory: https://ishares.com |
Source: sets.json.6.dr |
String found in binary or memory: https://jagran.com |
Source: sets.json.6.dr |
String found in binary or memory: https://journaldesfemmes.com |
Source: sets.json.6.dr |
String found in binary or memory: https://journaldesfemmes.fr |
Source: sets.json.6.dr |
String found in binary or memory: https://journaldunet.com |
Source: sets.json.6.dr |
String found in binary or memory: https://journaldunet.fr |
Source: sets.json.6.dr |
String found in binary or memory: https://joyreactor.cc |
Source: sets.json.6.dr |
String found in binary or memory: https://joyreactor.com |
Source: sets.json.6.dr |
String found in binary or memory: https://kaksya.in |
Source: sets.json.6.dr |
String found in binary or memory: https://kompas.com |
Source: sets.json.6.dr |
String found in binary or memory: https://kompas.tv |
Source: sets.json.6.dr |
String found in binary or memory: https://kompasiana.com |
Source: sets.json.6.dr |
String found in binary or memory: https://lanacion.com.ar |
Source: sets.json.6.dr |
String found in binary or memory: https://landyrev.com |
Source: sets.json.6.dr |
String found in binary or memory: https://landyrev.ru |
Source: sets.json.6.dr |
String found in binary or memory: https://laprensagrafica.com |
Source: sets.json.6.dr |
String found in binary or memory: https://lateja.cr |
Source: sets.json.6.dr |
String found in binary or memory: https://libero.it |
Source: sets.json.6.dr |
String found in binary or memory: https://linternaute.com |
Source: sets.json.6.dr |
String found in binary or memory: https://linternaute.fr |
Source: sets.json.6.dr |
String found in binary or memory: https://livehindustan.com |
Source: sets.json.6.dr |
String found in binary or memory: https://livemint.com |
Source: sets.json.6.dr |
String found in binary or memory: https://max.auto |
Source: sets.json.6.dr |
String found in binary or memory: https://medonet.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.cl |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.co.cr |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.ar |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.bo |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.co |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.do |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.ec |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.gt |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.hn |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.mx |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.ni |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.pa |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.pe |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.py |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.sv |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolibre.com.ve |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolivre.com |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadolivre.com.br |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.cl |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.ar |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.br |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.co |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.ec |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.mx |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.pe |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadopago.com.ve |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.cl |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.com |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.com.ar |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.com.br |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.com.co |
Source: sets.json.6.dr |
String found in binary or memory: https://mercadoshops.com.mx |
Source: sets.json.6.dr |
String found in binary or memory: https://mighty-app.appspot.com |
Source: sets.json.6.dr |
String found in binary or memory: https://mightytext.net |
Source: sets.json.6.dr |
String found in binary or memory: https://mittanbud.no |
Source: sets.json.6.dr |
String found in binary or memory: https://money.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://mystudentdashboard.com |
Source: sets.json.6.dr |
String found in binary or memory: https://nacion.com |
Source: sets.json.6.dr |
String found in binary or memory: https://nidhiacademyonline.com |
Source: sets.json.6.dr |
String found in binary or memory: https://nien.co |
Source: sets.json.6.dr |
String found in binary or memory: https://nien.com |
Source: sets.json.6.dr |
String found in binary or memory: https://nien.org |
Source: sets.json.6.dr |
String found in binary or memory: https://noticiascaracol.com |
Source: sets.json.6.dr |
String found in binary or memory: https://nourishingpursuits.com |
Source: sets.json.6.dr |
String found in binary or memory: https://o2.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://ocdn.eu |
Source: sets.json.6.dr |
String found in binary or memory: https://onet.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://ottplay.com |
Source: sets.json.6.dr |
String found in binary or memory: https://paula.com.uy |
Source: sets.json.6.dr |
String found in binary or memory: https://pdmp-apis.no |
Source: sets.json.6.dr |
String found in binary or memory: https://phonandroid.com |
Source: sets.json.6.dr |
String found in binary or memory: https://player.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://plejada.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://poalim.site |
Source: sets.json.6.dr |
String found in binary or memory: https://poalim.xyz |
Source: sets.json.6.dr |
String found in binary or memory: https://portalinmobiliario.com |
Source: sets.json.6.dr |
String found in binary or memory: https://prisjakt.no |
Source: sets.json.6.dr |
String found in binary or memory: https://pudelek.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://punjabijagran.com |
Source: sets.json.6.dr |
String found in binary or memory: https://radio1.be |
Source: sets.json.6.dr |
String found in binary or memory: https://radio2.be |
Source: sets.json.6.dr |
String found in binary or memory: https://reactor.cc |
Source: sets.json.6.dr |
String found in binary or memory: https://repid.org |
Source: sets.json.6.dr |
String found in binary or memory: https://reshim.org |
Source: sets.json.6.dr |
String found in binary or memory: https://rws1nvtvt.com |
Source: sets.json.6.dr |
String found in binary or memory: https://rws2nvtvt.com |
Source: sets.json.6.dr |
String found in binary or memory: https://rws3nvtvt.com |
Source: sets.json.6.dr |
String found in binary or memory: https://salemoveadvisor.com |
Source: sets.json.6.dr |
String found in binary or memory: https://salemovefinancial.com |
Source: sets.json.6.dr |
String found in binary or memory: https://salemovetravel.com |
Source: sets.json.6.dr |
String found in binary or memory: https://samayam.com |
Source: sets.json.6.dr |
String found in binary or memory: https://shock.co |
Source: sets.json.6.dr |
String found in binary or memory: https://smoney.vn |
Source: sets.json.6.dr |
String found in binary or memory: https://songshare.com |
Source: sets.json.6.dr |
String found in binary or memory: https://songstats.com |
Source: sets.json.6.dr |
String found in binary or memory: https://sporza.be |
Source: sets.json.6.dr |
String found in binary or memory: https://standardsandpraiserepurpose.com |
Source: sets.json.6.dr |
String found in binary or memory: https://startupislandtaiwan.com |
Source: sets.json.6.dr |
String found in binary or memory: https://startupislandtaiwan.net |
Source: sets.json.6.dr |
String found in binary or memory: https://startupislandtaiwan.org |
Source: sets.json.6.dr |
String found in binary or memory: https://stripe.com |
Source: sets.json.6.dr |
String found in binary or memory: https://stripe.network |
Source: sets.json.6.dr |
String found in binary or memory: https://stripecdn.com |
Source: sets.json.6.dr |
String found in binary or memory: https://supereva.it |
Source: sets.json.6.dr |
String found in binary or memory: https://talkdeskqaid.com |
Source: sets.json.6.dr |
String found in binary or memory: https://talkdeskstgid.com |
Source: sets.json.6.dr |
String found in binary or memory: https://teacherdashboard.com |
Source: sets.json.6.dr |
String found in binary or memory: https://technology-revealed.com |
Source: sets.json.6.dr |
String found in binary or memory: https://textyserver.appspot.com |
Source: sets.json.6.dr |
String found in binary or memory: https://timesinternet.in |
Source: sets.json.6.dr |
String found in binary or memory: https://timesofindia.com |
Source: sets.json.6.dr |
String found in binary or memory: https://tribunnews.com |
Source: sets.json.6.dr |
String found in binary or memory: https://trytalkdesk.com |
Source: sets.json.6.dr |
String found in binary or memory: https://tucarro.com |
Source: sets.json.6.dr |
String found in binary or memory: https://tucarro.com.co |
Source: sets.json.6.dr |
String found in binary or memory: https://tucarro.com.ve |
Source: sets.json.6.dr |
String found in binary or memory: https://tvid.in |
Source: sets.json.6.dr |
String found in binary or memory: https://tvn.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://tvn24.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://unotv.com |
Source: file.bat |
String found in binary or memory: https://valuable-gazette-shock-medication.trycloudflare.com/SCANNED.pdf |
Source: sets.json.6.dr |
String found in binary or memory: https://victorymedium.com |
Source: sets.json.6.dr |
String found in binary or memory: https://vrt.be |
Source: sets.json.6.dr |
String found in binary or memory: https://vwo.com |
Source: sets.json.6.dr |
String found in binary or memory: https://welt.de |
Source: sets.json.6.dr |
String found in binary or memory: https://wieistmeineip.de |
Source: sets.json.6.dr |
String found in binary or memory: https://wildix.com |
Source: sets.json.6.dr |
String found in binary or memory: https://wildixin.com |
Source: sets.json.6.dr |
String found in binary or memory: https://wingify.com |
Source: sets.json.6.dr |
String found in binary or memory: https://wordle.at |
Source: sets.json.6.dr |
String found in binary or memory: https://wp.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://wpext.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://www.asadcdn.com |
Source: sets.json.6.dr |
String found in binary or memory: https://ya.ru |
Source: sets.json.6.dr |
String found in binary or memory: https://zalo.me |
Source: sets.json.6.dr |
String found in binary or memory: https://zdrowietvn.pl |
Source: sets.json.6.dr |
String found in binary or memory: https://zingmp3.vn |
Source: unknown |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\file.bat" " |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K "C:\Users\user\Desktop\file.bat" MY_FLAG |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://valuable-gazette-shock-medication.trycloudflare.com/SCANNED.pdf |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\kam.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\las.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\zap.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\sample.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\xff.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\time.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\upload.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2684 --field-trial-handle=2636,i,6799672374632597056,542459975997173422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\update.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\info.cmd"" |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /K "C:\Users\user\Desktop\file.bat" MY_FLAG |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://valuable-gazette-shock-medication.trycloudflare.com/SCANNED.pdf |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\kam.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\las.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\zap.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\sample.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\xff.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\time.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\upload.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\update.cmd"" |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\cmd.exe cmd /c ""C:\Users\user\Pictures\info.cmd"" |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2684 --field-trial-handle=2636,i,6799672374632597056,542459975997173422,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.shell.servicehostbuilder.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: ieframe.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: policymanager.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: msvcp110_win.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: sfc_os.dll |
Jump to behavior |