| Time & API |
Arguments |
Status |
Return |
Repeated |
1619781436.108875
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xjzpva.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\xjzpva.exe
show_type:
0
|
success
|
1 |
0
|
1619781441.014875
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619781441.014875
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619791641.026501
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xjzpva.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xjzpva.exe
show_type:
0
|
success
|
1 |
0
|
1619791666.025876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\011122.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\011122.exe
show_type:
0
|
success
|
1 |
0
|
1619791669.134876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\502968.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\502968.exe
show_type:
0
|
success
|
1 |
0
|
1619791672.196876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\761767.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\761767.exe
show_type:
0
|
success
|
1 |
0
|
1619791675.259876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\742218.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\742218.exe
show_type:
0
|
success
|
1 |
0
|
1619791678.384876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\232923.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\232923.exe
show_type:
0
|
success
|
1 |
0
|
1619791681.587876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\631535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\631535.exe
show_type:
0
|
success
|
1 |
0
|
1619791684.665876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\606319.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\606319.exe
show_type:
0
|
success
|
1 |
0
|
1619791687.884876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\952591.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\952591.exe
show_type:
0
|
success
|
1 |
0
|
1619791693.759876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\250330.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\250330.exe
show_type:
0
|
success
|
1 |
0
|
1619791698.165876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\671633.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\671633.exe
show_type:
0
|
success
|
1 |
0
|
1619791703.650876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\277908.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\277908.exe
show_type:
0
|
success
|
1 |
0
|
1619791708.728876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\847878.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\847878.exe
show_type:
0
|
success
|
1 |
0
|
1619791712.025876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\346310.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\346310.exe
show_type:
0
|
success
|
1 |
0
|
1619791717.618876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\925399.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\925399.exe
show_type:
0
|
success
|
1 |
0
|
1619791723.993876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\694069.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\694069.exe
show_type:
0
|
success
|
1 |
0
|
1619791728.040876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\862531.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\862531.exe
show_type:
0
|
success
|
1 |
0
|
1619791732.634876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\261215.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\261215.exe
show_type:
0
|
success
|
1 |
0
|
1619791739.759876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\495472.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\495472.exe
show_type:
0
|
success
|
1 |
0
|
1619791754.306876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\394861.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\394861.exe
show_type:
0
|
success
|
1 |
0
|
1619791759.540876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\312803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\312803.exe
show_type:
0
|
success
|
1 |
0
|
1619791772.056876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541871.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541871.exe
show_type:
0
|
success
|
1 |
0
|
1619791785.025876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\644971.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\644971.exe
show_type:
0
|
success
|
1 |
0
|
1619791789.540876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386905.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386905.exe
show_type:
0
|
success
|
1 |
0
|
1619791796.353876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\754353.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\754353.exe
show_type:
0
|
success
|
1 |
0
|
1619791799.462876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782595.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782595.exe
show_type:
0
|
success
|
1 |
0
|
1619791802.634876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\031494.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\031494.exe
show_type:
0
|
success
|
1 |
0
|
1619791805.696876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\881552.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\881552.exe
show_type:
0
|
success
|
1 |
0
|
1619791808.712876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\992803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\992803.exe
show_type:
0
|
success
|
1 |
0
|
1619791811.821876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\156993.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\156993.exe
show_type:
0
|
success
|
1 |
0
|
1619791814.915876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\650402.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\650402.exe
show_type:
0
|
success
|
1 |
0
|
1619791818.087876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\751753.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\751753.exe
show_type:
0
|
success
|
1 |
0
|
1619791821.290876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\227817.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\227817.exe
show_type:
0
|
success
|
1 |
0
|
1619791825.837876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\586614.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\586614.exe
show_type:
0
|
success
|
1 |
0
|
1619791830.743876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\884967.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\884967.exe
show_type:
0
|
success
|
1 |
0
|
1619791834.275876
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\144711.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\144711.exe
show_type:
0
|
success
|
1 |
0
|
1619791666.260249
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\011122.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\011122.exe
show_type:
0
|
success
|
1 |
0
|
1619791669.401626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\502968.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\502968.exe
show_type:
0
|
success
|
1 |
0
|
1619791672.431751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\761767.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\761767.exe
show_type:
0
|
success
|
1 |
0
|
1619791675.494626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\742218.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\742218.exe
show_type:
0
|
success
|
1 |
0
|
1619791678.619626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\232923.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\232923.exe
show_type:
0
|
success
|
1 |
0
|
1619791681.932374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\631535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\631535.exe
show_type:
0
|
success
|
1 |
0
|
1619791684.931876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\606319.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\606319.exe
show_type:
0
|
success
|
1 |
0
|
1619791688.271063
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\952591.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\952591.exe
show_type:
0
|
success
|
1 |
0
|
1619791694.75075
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\250330.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\250330.exe
show_type:
0
|
success
|
1 |
0
|
1619791699.791838
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\671633.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\671633.exe
show_type:
0
|
success
|
1 |
0
|
1619791706.521914
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\277908.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\277908.exe
show_type:
0
|
success
|
1 |
0
|