| Time & API |
Arguments |
Status |
Return |
Repeated |
1619649230.950334
CreateProcessInternalW
|
thread_identifier:
1164
thread_handle:
0x00000100
process_identifier:
2288
current_directory:
filepath:
track:
1
command_line:
cmd /C wmic.exe SHADOWCOPY DELETE /nointeractive
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649237.919334
CreateProcessInternalW
|
thread_identifier:
3160
thread_handle:
0x00000100
process_identifier:
3156
current_directory:
filepath:
track:
1
command_line:
cmd /C wbadmin DELETE SYSTEMSTATEBACKUP
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649238.997334
CreateProcessInternalW
|
thread_identifier:
3240
thread_handle:
0x00000100
process_identifier:
3236
current_directory:
filepath:
track:
1
command_line:
cmd /C wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldest
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649240.059334
CreateProcessInternalW
|
thread_identifier:
3324
thread_handle:
0x00000100
process_identifier:
3320
current_directory:
filepath:
track:
1
command_line:
cmd /C bcdedit.exe /set {default} recoveryenabled No
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649241.122334
CreateProcessInternalW
|
thread_identifier:
3408
thread_handle:
0x00000100
process_identifier:
3404
current_directory:
filepath:
track:
1
command_line:
cmd /C bcdedit.exe /set {default} bootstatuspolicy ignoreallfailures
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649242.247334
CreateProcessInternalW
|
thread_identifier:
3492
thread_handle:
0x00000100
process_identifier:
3488
current_directory:
filepath:
track:
1
command_line:
cmd /C vssadmin.exe Delete Shadows /All /Quiet
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649244.825334
CreateProcessInternalW
|
thread_identifier:
3672
thread_handle:
0x00000100
process_identifier:
3668
current_directory:
filepath:
track:
1
command_line:
cmd /C C:\Windows\system32\vssvc.exe
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649245.872334
CreateProcessInternalW
|
thread_identifier:
3752
thread_handle:
0x00000100
process_identifier:
3748
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM wxServer*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649248.934334
CreateProcessInternalW
|
thread_identifier:
3980
thread_handle:
0x00000100
process_identifier:
3976
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM wxServerView*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649251.528334
CreateProcessInternalW
|
thread_identifier:
1320
thread_handle:
0x00000100
process_identifier:
1880
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM sqlmangr*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649254.184334
CreateProcessInternalW
|
thread_identifier:
3268
thread_handle:
0x00000100
process_identifier:
3248
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM RAgui*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649256.887334
CreateProcessInternalW
|
thread_identifier:
3436
thread_handle:
0x00000100
process_identifier:
3420
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM supervise*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649259.559334
CreateProcessInternalW
|
thread_identifier:
3492
thread_handle:
0x00000100
process_identifier:
3540
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM Culture*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649262.278334
CreateProcessInternalW
|
thread_identifier:
3084
thread_handle:
0x00000100
process_identifier:
4072
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM Defwatch*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649276.419334
CreateProcessInternalW
|
thread_identifier:
2412
thread_handle:
0x00000100
process_identifier:
3384
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM winword*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649279.309334
CreateProcessInternalW
|
thread_identifier:
3120
thread_handle:
0x00000100
process_identifier:
3616
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM QBW32*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649282.044334
CreateProcessInternalW
|
thread_identifier:
3744
thread_handle:
0x00000100
process_identifier:
2956
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM QBDBMgr*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649284.872334
CreateProcessInternalW
|
thread_identifier:
1752
thread_handle:
0x00000100
process_identifier:
3208
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM qbupdate*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|
1619649305.372334
CreateProcessInternalW
|
thread_identifier:
3964
thread_handle:
0x00000100
process_identifier:
3452
current_directory:
filepath:
track:
1
command_line:
cmd /C taskkill /F /T /IM axlbridge*
filepath_r:
stack_pivoted:
0
creation_flags:
134217728
(CREATE_NO_WINDOW)
process_handle:
0x00000104
inherit_handles:
0
|
success
|
1 |
0
|