| Time & API |
Arguments |
Status |
Return |
Repeated |
1619596035.293698
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\pbkhoy.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\pbkhoy.exe
show_type:
0
|
success
|
1 |
0
|
1619596039.700698
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619596039.700698
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619624767.78125
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\pbkhoy.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\pbkhoy.exe
show_type:
0
|
success
|
1 |
0
|
1619624777.468625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\830046.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\830046.exe
show_type:
0
|
success
|
1 |
0
|
1619624781.905625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\685687.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\685687.exe
show_type:
0
|
success
|
1 |
0
|
1619624787.187625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\927179.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\927179.exe
show_type:
0
|
success
|
1 |
0
|
1619624791.843625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\071031.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\071031.exe
show_type:
0
|
success
|
1 |
0
|
1619624796.593625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\887390.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\887390.exe
show_type:
0
|
success
|
1 |
0
|
1619624800.968625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\151975.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\151975.exe
show_type:
0
|
success
|
1 |
0
|
1619624805.171625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\625535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\625535.exe
show_type:
0
|
success
|
1 |
0
|
1619624810.218625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\871901.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\871901.exe
show_type:
0
|
success
|
1 |
0
|
1619624814.734625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\242652.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\242652.exe
show_type:
0
|
success
|
1 |
0
|
1619624818.359625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\543923.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\543923.exe
show_type:
0
|
success
|
1 |
0
|
1619624821.890625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\111837.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\111837.exe
show_type:
0
|
success
|
1 |
0
|
1619624825.234625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\610940.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\610940.exe
show_type:
0
|
success
|
1 |
0
|
1619624828.859625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\356803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\356803.exe
show_type:
0
|
success
|
1 |
0
|
1619624832.530625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162457.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162457.exe
show_type:
0
|
success
|
1 |
0
|
1619624838.796625
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\089917.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\089917.exe
show_type:
0
|
success
|
1 |
0
|
1619624778.016125
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\830046.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\830046.exe
show_type:
0
|
success
|
1 |
0
|
1619624782.499875
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\685687.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\685687.exe
show_type:
0
|
success
|
1 |
0
|
1619624788.421625
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\927179.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\927179.exe
show_type:
0
|
success
|
1 |
0
|
1619624794.3745
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\071031.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\071031.exe
show_type:
0
|
success
|
1 |
0
|
1619624799.07825
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\887390.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\887390.exe
show_type:
0
|
success
|
1 |
0
|
1619624802.952875
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\151975.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\151975.exe
show_type:
0
|
success
|
1 |
0
|
1619624807.1555
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\625535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\625535.exe
show_type:
0
|
success
|
1 |
0
|
1619624810.594125
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\871901.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\871901.exe
show_type:
0
|
success
|
1 |
0
|
1619624815.14075
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\242652.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\242652.exe
show_type:
0
|
success
|
1 |
0
|
1619624818.624875
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\543923.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\543923.exe
show_type:
0
|
success
|
1 |
0
|
1619624822.266125
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\111837.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\111837.exe
show_type:
0
|
success
|
1 |
0
|
1619624825.500125
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\610940.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\610940.exe
show_type:
0
|
success
|
1 |
0
|
1619624829.1875
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\356803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\356803.exe
show_type:
0
|
success
|
1 |
0
|
1619624833.4845
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162457.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162457.exe
show_type:
0
|
success
|
1 |
0
|