| Time & API |
Arguments |
Status |
Return |
Repeated |
1619781432.093625
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ncsvhi.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\ncsvhi.exe
show_type:
0
|
success
|
1 |
0
|
1619781440.031625
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619781440.031625
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619792943.583124
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ncsvhi.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ncsvhi.exe
show_type:
0
|
success
|
1 |
0
|
1619792973.051249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\342650.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\342650.exe
show_type:
0
|
success
|
1 |
0
|
1619792976.176249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\161657.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\161657.exe
show_type:
0
|
success
|
1 |
0
|
1619792979.239249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\318756.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\318756.exe
show_type:
0
|
success
|
1 |
0
|
1619792982.395249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\153890.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\153890.exe
show_type:
0
|
success
|
1 |
0
|
1619792985.473249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\412970.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\412970.exe
show_type:
0
|
success
|
1 |
0
|
1619792990.333249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\548852.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\548852.exe
show_type:
0
|
success
|
1 |
0
|
1619792993.567249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\899173.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\899173.exe
show_type:
0
|
success
|
1 |
0
|
1619793002.770249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\958864.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\958864.exe
show_type:
0
|
success
|
1 |
0
|
1619793012.036249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\836697.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\836697.exe
show_type:
0
|
success
|
1 |
0
|
1619793016.333249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\517574.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\517574.exe
show_type:
0
|
success
|
1 |
0
|
1619793020.864249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\676687.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\676687.exe
show_type:
0
|
success
|
1 |
0
|
1619793026.348249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\628381.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\628381.exe
show_type:
0
|
success
|
1 |
0
|
1619793031.395249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\415182.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\415182.exe
show_type:
0
|
success
|
1 |
0
|
1619793036.192249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\700817.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\700817.exe
show_type:
0
|
success
|
1 |
0
|
1619793042.723249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\424675.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\424675.exe
show_type:
0
|
success
|
1 |
0
|
1619793051.520249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\276427.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\276427.exe
show_type:
0
|
success
|
1 |
0
|
1619793073.426249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\105518.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\105518.exe
show_type:
0
|
success
|
1 |
0
|
1619793081.723249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\119915.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\119915.exe
show_type:
0
|
success
|
1 |
0
|
1619793089.629249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\727770.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\727770.exe
show_type:
0
|
success
|
1 |
0
|
1619793097.520249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\552612.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\552612.exe
show_type:
0
|
success
|
1 |
0
|
1619793102.661249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\828758.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\828758.exe
show_type:
0
|
success
|
1 |
0
|
1619793107.848249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\578463.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\578463.exe
show_type:
0
|
success
|
1 |
0
|
1619793114.723249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\771918.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\771918.exe
show_type:
0
|
success
|
1 |
0
|
1619793126.458249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816984.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816984.exe
show_type:
0
|
success
|
1 |
0
|
1619793134.114249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\104173.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\104173.exe
show_type:
0
|
success
|
1 |
0
|
1619793143.270249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\418591.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\418591.exe
show_type:
0
|
success
|
1 |
0
|
1619793151.754249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\778381.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\778381.exe
show_type:
0
|
success
|
1 |
0
|
1619793156.864249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\327864.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\327864.exe
show_type:
0
|
success
|
1 |
0
|
1619793162.208249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\013798.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\013798.exe
show_type:
0
|
success
|
1 |
0
|
1619793169.286249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\475474.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\475474.exe
show_type:
0
|
success
|
1 |
0
|
1619793176.676249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\957424.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\957424.exe
show_type:
0
|
success
|
1 |
0
|
1619793191.286249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750961.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750961.exe
show_type:
0
|
success
|
1 |
0
|
1619793198.958249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\912437.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\912437.exe
show_type:
0
|
success
|
1 |
0
|
1619793204.723249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\113938.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\113938.exe
show_type:
0
|
success
|
1 |
0
|
1619793211.208249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913869.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913869.exe
show_type:
0
|
success
|
1 |
0
|
1619793219.208249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\791332.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\791332.exe
show_type:
0
|
success
|
1 |
0
|
1619793228.520249
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\497247.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\497247.exe
show_type:
0
|
success
|
1 |
0
|
1619792973.301999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\342650.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\342650.exe
show_type:
0
|
success
|
1 |
0
|
1619792976.442999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\161657.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\161657.exe
show_type:
0
|
success
|
1 |
0
|
1619792979.708501
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\318756.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\318756.exe
show_type:
0
|
success
|
1 |
0
|
1619792982.583124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\153890.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\153890.exe
show_type:
0
|
success
|
1 |
0
|
1619792985.676876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\412970.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\412970.exe
show_type:
0
|
success
|
1 |
0
|
1619792990.640938
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\548852.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\548852.exe
show_type:
0
|
success
|
1 |
0
|
1619792994.336375
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\899173.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\899173.exe
show_type:
0
|
success
|
1 |
0
|
1619793004.025437
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\958864.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\958864.exe
show_type:
0
|
success
|
1 |
0
|
1619793013.538063
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\836697.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\836697.exe
show_type:
0
|
success
|
1 |
0
|