Source: unknown | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\wp.bat" " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((,.,/((((((((((((((((((((/, */ [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,*/((((((((((((((((((/, [92m.*//((//**, [32m .*((((((* [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((((/* [94m****************** [32m/####### [32m.(. (((((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((. [92m. [94m****************** [97m/@@@@@/ [94m*** [92m/###### [32m /(((((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,,. [92m. [94m********************** [97m@@@@@@@@@@( [94m*** [92m,#### [32m ../((((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m, , [92m [94m********************** [97m#@@@@@#@@@@ [94m********* [92m## [32m((/ /(((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m..(( [92m(########## [94m********* [97m/#@@@@@@@@@/ [94m************* [32m,,..(((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(################(/ [94m****** [97m/@@@@@# [94m**************** [32m.. /(( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(########################(/ [94m************************ [32m..*( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(#############################(/ [94m******************** [32m.,( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################################(/ [94m*************** [32m..( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######################################( [94m************ [32m..( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######(,.***.,(###################(..***(/ [94m********* [32m..( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######*(#####((##################((######/( [94m******** [32m..( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################(/**********(################( [94m** [32m...( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(####################/*******(################### [32m.(((( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(((( [92m(############################################/ [32m /(( [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m..(((( [92m(#########################################( [32m..(((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m......(((( [92m(#################################( [32m .(((((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((. , [92m(############################( [32m../(((((((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/, [92m,####################( [32m/..((((((((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/,. [92m,*//////*,. [32m ./(((((((((((. [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((((((((((((((((((((/ [97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mAny misuse of this software will not be the responsibility of the author or of any other collaborator. [40;97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mUse it at your own networks and/or with the network owner's permission. [40;97m | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | |
Source: C:\Windows\System32\forfiles.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [33m[+] [97m WINDOWS OS | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wbem\WMIC.exe wmic qfe get Caption,Description,HotFixID,InstalledOn | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i "2000 XP 2003 2008 vista" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i /C:"windows 7" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i "2000 XP 2003 2008 vista" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i /C:"windows 7" | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((,.,/((((((((((((((((((((/, */ [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wbem\WMIC.exe wmic qfe get Caption,Description,HotFixID,InstalledOn | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(#############################(/ [94m******************** [32m.,( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i /C:"windows 7" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################################(/ [94m*************** [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######(,.***.,(###################(..***(/ [94m********* [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(####################/*******(################### [32m.(((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m......(((( [92m(#################################( [32m .(((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/, [92m,####################( [32m/..((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######################################( [94m************ [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/,. [92m,*//////*,. [32m ./(((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/, [92m,####################( [32m/..((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(################(/ [94m****** [97m/@@@@@# [94m**************** [32m.. /(( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######*(#####((##################((######/( [94m******** [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################(/**********(################( [94m** [32m...( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,,. [92m. [94m********************** [97m@@@@@@@@@@( [94m*** [92m,#### [32m ../((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mUse it at your own networks and/or with the network owner's permission. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((. [92m. [94m****************** [97m/@@@@@/ [94m*** [92m/###### [32m /(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [33m[+] [97m WINDOWS OS | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m..(((( [92m(#########################################( [32m..(((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######(,.***.,(###################(..***(/ [94m********* [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m, ,0x1B[92m0x1B[94m**********************0x1B[97m#@@@@@#@@@@0x1B[94m*********0x1B[92m##0x1B[32m((/ /((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((0x1B[92m(##########0x1B[94m*********0x1B[97m/#@@@@@@@@@/0x1B[94m*************0x1B[32m,,..((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######(,.***.,(###################(..***(/0x1B[94m*********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((,.,/((((((((((((((((((((/, */ [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mWinPEAS should be used for authorized penetration testing and/or educational purposes only.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\wbem\WMIC.exe wmic qfe get Caption,Description,HotFixID,InstalledOn | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(#############################(/ [94m******************** [32m.,( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\findstr.exe findstr /i /C:"windows 7" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################################(/ [94m*************** [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######(,.***.,(###################(..***(/ [94m********* [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(####################/*******(################### [32m.(((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m......(((( [92m(#################################( [32m .(((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/, [92m,####################( [32m/..((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[33m[+]0x1B[97m WINDOWS OS" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######################################( [94m************ [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/,. [92m,*//////*,. [32m ./(((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m....((((0x1B[92m(#####################################(0x1B[32m .((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((/, [92m,####################( [32m/..((((((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mAny misuse of this software will not be the responsibility of the author or of any other collaborator.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((.0x1B[92m.0x1B[94m******************0x1B[97m/@@@@@/0x1B[94m***0x1B[92m/######0x1B[32m /((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(( [92m(################(/ [94m****** [97m/@@@@@# [94m**************** [32m.. /(( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######*(#####((##################((######/( [94m******** [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(##################(/**********(################( [94m** [32m...( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/,. 0x1B[92m,*//////*,.0x1B[32m ./(((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,/*,..*(((((((((((((((((((((((((((((((((, [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,,.0x1B[92m.0x1B[94m**********************0x1B[97m@@@@@@@@@@(0x1B[94m***0x1B[92m,####0x1B[32m ../(((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO.0x1B[32m[*]0x1B[97m BASIC SYSTEM INFO" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[41mUse it at your own networks and/or with the network owner's permission.0x1B[40;97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,,. [92m. [94m********************** [97m@@@@@@@@@@( [94m*** [92m,#### [32m ../((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######################################(0x1B[94m************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m..((((0x1B[92m(#########################################(0x1B[32m..(((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m....(((( [92m(#####################################( [32m .((((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((,.,/((((((((((((((((((((/, */0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mUse it at your own networks and/or with the network owner's permission. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((. [92m. [94m****************** [97m/@@@@@/ [94m*** [92m/###### [32m /(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [33m[+] [97m WINDOWS OS | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m..(((( [92m(#########################################( [32m..(((((. [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\systeminfo.exe systeminfo | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."Microsoft Windows 10 Pro " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(######(,.***.,(###################(..***(/ [94m********* [32m..( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((. ,0x1B[92m(############################(0x1B[32m../(((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,*/((((((((((((((((((/, [92m.*//((//**, [32m .*((((((* [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,*/((((((((((((((((((/, 0x1B[92m.*//((//**,0x1B[32m .*((((((*0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mUse it at your own networks and/or with the network owner's permission. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(################(/0x1B[94m******0x1B[97m/@@@@@#0x1B[94m****************0x1B[32m.. /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(#############################(/0x1B[94m********************0x1B[32m.,(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.( [92m(#############################(/ [94m******************** [32m.,( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################################(/0x1B[94m***************0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(######*(#####((##################((######/(0x1B[94m********0x1B[32m..(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(##################(/**********(################(0x1B[94m**0x1B[32m...(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((0x1B[92m(####################/*******(###################0x1B[32m.((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m.(((( [92m(############################################/ [32m /(( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.((((0x1B[92m(############################################/0x1B[32m /((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m......((((0x1B[92m(#################################(0x1B[32m .(((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((/, 0x1B[92m,####################(0x1B[32m/..((((((((((.0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((((((((((((((((((/0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((,.,/((((((((((((((((((((/, */ [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m,/*,..*(((((((((((((((((((((((((((((((((,0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m((((((((((((((((* 0x1B[94m*****0x1B[32m,,,/########## 0x1B[32m.(* ,((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m(((((((((((((((((((((((((((/ [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [41mWinPEAS should be used for authorized penetration testing and/or educational purposes only. [40;97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\forfiles.exe FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m(((((((((((/* 0x1B[94m******************0x1B[32m/####### 0x1B[32m.(. ((((((0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m[*] [97m BASIC SYSTEM INFO | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m((((((((((((((((* [94m***** [32m,,,/########## [32m.(* ,(((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe /C ECHO. [32m,,. [92m. [94m********************** [97m@@@@@@@@@@( [94m*** [92m,#### [32m ../((((( [97m | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c FORFILES.EXE /P C:\Users\user\Desktop\ /M wp.bat /C "CMD /C ECHO. 0x1B[32m.(0x1B[92m(########################(/0x1B[94m************************0x1B[32m..*(0x1B[97m" | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\more.com more | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" ECHO."user-PC " " | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: unknown unknown | Jump to behavior |