Time & API |
Arguments |
Status |
Return |
Repeated |
1621017117.184876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017117.184876
WriteConsoleW
|
buffer:
systeminfo
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017117.199876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\1.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017137.777876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017137.777876
WriteConsoleW
|
buffer:
ipconfig
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017137.793876
WriteConsoleW
|
buffer:
/all
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017137.809876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\2.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017145.559876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017145.559876
WriteConsoleW
|
buffer:
net
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017145.574876
WriteConsoleW
|
buffer:
config workstation
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017145.574876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\3.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017147.590876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017147.590876
WriteConsoleW
|
buffer:
arp
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017147.621876
WriteConsoleW
|
buffer:
-a
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017147.621876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\4.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.449876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.449876
WriteConsoleW
|
buffer:
nbtstat
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.449876
WriteConsoleW
|
buffer:
/n
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.449876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\5.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.480876
WriteConsoleW
|
buffer:
'nbtstat' 不是内部或外部命令,也不是可运行的程序
或批处理文件。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1621017149.512876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.512876
WriteConsoleW
|
buffer:
net
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.512876
WriteConsoleW
|
buffer:
view /all
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017149.512876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\6.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017153.980876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017153.980876
WriteConsoleW
|
buffer:
net
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017153.980876
WriteConsoleW
|
buffer:
view /all /domain
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017153.980876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\7.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017154.980876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017154.980876
WriteConsoleW
|
buffer:
nltest
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017154.980876
WriteConsoleW
|
buffer:
/domain_trusts
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017154.980876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\8.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.043876
WriteConsoleW
|
buffer:
'nltest' 不是内部或外部命令,也不是可运行的程序
或批处理文件。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1621017155.074876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.074876
WriteConsoleW
|
buffer:
nltest
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.074876
WriteConsoleW
|
buffer:
/domain_trusts /all_trusts
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.074876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\9.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.105876
WriteConsoleW
|
buffer:
'nltest' 不是内部或外部命令,也不是可运行的程序
或批处理文件。
console_handle:
0x0000000b
|
success
|
1 |
0
|
1621017155.105876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.121876
WriteConsoleW
|
buffer:
tasklist
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.121876
WriteConsoleW
|
buffer:
/v /fo "TABLE"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017155.121876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\10.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017157.309876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017157.309876
WriteConsoleW
|
buffer:
dsquery.exe
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017157.309876
WriteConsoleW
|
buffer:
* -filter "objectcategory=computer" -attr dNSHostName distinguishedName description -limit 0
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017157.309876
WriteConsoleW
|
buffer:
"C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hTypeSock_TMP\11.csv"
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017162.262876
WriteConsoleW
|
buffer:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\hTypeSock_TMP>
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017162.262876
WriteConsoleW
|
buffer:
exit
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017162.277876
WriteConsoleW
|
buffer:
/B
console_handle:
0x00000007
|
success
|
1 |
0
|
1621017118.137374
WriteConsoleW
|
buffer:
正在加载操作系统信息...
console_handle:
0x0000000b
|
success
|
1 |
0
|