| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826884.233895
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\uwtoee.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\uwtoee.exe
show_type:
0
|
success
|
1 |
0
|
1619826888.842895
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619826888.842895
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619837147.077626
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\uwtoee.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\uwtoee.exe
show_type:
0
|
success
|
1 |
0
|
1619837155.499999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913535.exe
show_type:
0
|
success
|
1 |
0
|
1619837159.889999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\016245.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\016245.exe
show_type:
0
|
success
|
1 |
0
|
1619837163.436999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782711.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782711.exe
show_type:
0
|
success
|
1 |
0
|
1619837167.295999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\765594.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\765594.exe
show_type:
0
|
success
|
1 |
0
|
1619837170.842999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\842339.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\842339.exe
show_type:
0
|
success
|
1 |
0
|
1619837175.217999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\143446.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\143446.exe
show_type:
0
|
success
|
1 |
0
|
1619837183.295999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\516195.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\516195.exe
show_type:
0
|
success
|
1 |
0
|
1619837186.905999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\160196.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\160196.exe
show_type:
0
|
success
|
1 |
0
|
1619837190.077999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831110.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831110.exe
show_type:
0
|
success
|
1 |
0
|
1619837193.295999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\946709.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\946709.exe
show_type:
0
|
success
|
1 |
0
|
1619837196.530999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\032497.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\032497.exe
show_type:
0
|
success
|
1 |
0
|
1619837199.764999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\230823.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\230823.exe
show_type:
0
|
success
|
1 |
0
|
1619837202.936999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\417523.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\417523.exe
show_type:
0
|
success
|
1 |
0
|
1619837206.124999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\122959.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\122959.exe
show_type:
0
|
success
|
1 |
0
|
1619837209.577999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\097732.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\097732.exe
show_type:
0
|
success
|
1 |
0
|
1619837213.186999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\283575.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\283575.exe
show_type:
0
|
success
|
1 |
0
|
1619837220.014999
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\535956.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\535956.exe
show_type:
0
|
success
|
1 |
0
|
1619837155.795751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913535.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\913535.exe
show_type:
0
|
success
|
1 |
0
|
1619837160.170999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\016245.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\016245.exe
show_type:
0
|
success
|
1 |
0
|
1619837163.795999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782711.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\782711.exe
show_type:
0
|
success
|
1 |
0
|
1619837168.125249
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\765594.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\765594.exe
show_type:
0
|
success
|
1 |
0
|
1619837171.312249
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\842339.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\842339.exe
show_type:
0
|
success
|
1 |
0
|
1619837176.202374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\143446.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\143446.exe
show_type:
0
|
success
|
1 |
0
|
1619837184.092999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\516195.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\516195.exe
show_type:
0
|
success
|
1 |
0
|
1619837187.202751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\160196.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\160196.exe
show_type:
0
|
success
|
1 |
0
|
1619837190.342999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831110.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831110.exe
show_type:
0
|
success
|
1 |
0
|
1619837193.592751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\946709.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\946709.exe
show_type:
0
|
success
|
1 |
0
|
1619837196.827374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\032497.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\032497.exe
show_type:
0
|
success
|
1 |
0
|
1619837200.092751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\230823.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\230823.exe
show_type:
0
|
success
|
1 |
0
|
1619837203.249374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\417523.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\417523.exe
show_type:
0
|
success
|
1 |
0
|
1619837206.609124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\122959.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\122959.exe
show_type:
0
|
success
|
1 |
0
|
1619837210.014499
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\097732.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\097732.exe
show_type:
0
|
success
|
1 |
0
|
1619837214.030874
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\283575.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\283575.exe
show_type:
0
|
success
|
1 |
0
|
1619837220.467751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\535956.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\535956.exe
show_type:
0
|
success
|
1 |
0
|