| Time & API |
Arguments |
Status |
Return |
Repeated |
1619826887.617988
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\lcybpk.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\lcybpk.exe
show_type:
0
|
success
|
1 |
0
|
1619826891.898988
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619826891.898988
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619851711.628374
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\lcybpk.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\lcybpk.exe
show_type:
0
|
success
|
1 |
0
|
1619851720.534751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\611293.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\611293.exe
show_type:
0
|
success
|
1 |
0
|
1619851724.503751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\731208.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\731208.exe
show_type:
0
|
success
|
1 |
0
|
1619851728.003751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\241389.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\241389.exe
show_type:
0
|
success
|
1 |
0
|
1619851731.456751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386399.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386399.exe
show_type:
0
|
success
|
1 |
0
|
1619851735.237751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\313957.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\313957.exe
show_type:
0
|
success
|
1 |
0
|
1619851739.065751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\987129.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\987129.exe
show_type:
0
|
success
|
1 |
0
|
1619851743.784751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\269101.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\269101.exe
show_type:
0
|
success
|
1 |
0
|
1619851749.612751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\075350.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\075350.exe
show_type:
0
|
success
|
1 |
0
|
1619851755.175751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\665169.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\665169.exe
show_type:
0
|
success
|
1 |
0
|
1619851759.253751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\931215.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\931215.exe
show_type:
0
|
success
|
1 |
0
|
1619851763.237751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816536.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816536.exe
show_type:
0
|
success
|
1 |
0
|
1619851766.456751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\237200.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\237200.exe
show_type:
0
|
success
|
1 |
0
|
1619851769.675751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\190084.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\190084.exe
show_type:
0
|
success
|
1 |
0
|
1619851772.831751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\129156.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\129156.exe
show_type:
0
|
success
|
1 |
0
|
1619851776.065751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\010128.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\010128.exe
show_type:
0
|
success
|
1 |
0
|
1619851780.581751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\445175.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\445175.exe
show_type:
0
|
success
|
1 |
0
|
1619851787.003751
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\484472.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\484472.exe
show_type:
0
|
success
|
1 |
0
|
1619851720.877999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\611293.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\611293.exe
show_type:
0
|
success
|
1 |
0
|
1619851724.862501
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\731208.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\731208.exe
show_type:
0
|
success
|
1 |
0
|
1619851728.378876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\241389.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\241389.exe
show_type:
0
|
success
|
1 |
0
|
1619851731.894626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386399.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386399.exe
show_type:
0
|
success
|
1 |
0
|
1619851735.675124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\313957.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\313957.exe
show_type:
0
|
success
|
1 |
0
|
1619851739.847751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\987129.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\987129.exe
show_type:
0
|
success
|
1 |
0
|
1619851744.940876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\269101.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\269101.exe
show_type:
0
|
success
|
1 |
0
|
1619851755.019374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\075350.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\075350.exe
show_type:
0
|
success
|
1 |
0
|
1619851758.705999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\665169.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\665169.exe
show_type:
0
|
success
|
1 |
0
|
1619851761.174999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\931215.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\931215.exe
show_type:
0
|
success
|
1 |
0
|
1619851763.690124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816536.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\816536.exe
show_type:
0
|
success
|
1 |
0
|
1619851766.800249
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\237200.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\237200.exe
show_type:
0
|
success
|
1 |
0
|
1619851769.956751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\190084.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\190084.exe
show_type:
0
|
success
|
1 |
0
|
1619851773.205999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\129156.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\129156.exe
show_type:
0
|
success
|
1 |
0
|
1619851776.753876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\010128.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\010128.exe
show_type:
0
|
success
|
1 |
0
|
1619851781.706124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\445175.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\445175.exe
show_type:
0
|
success
|
1 |
0
|
1619851787.972374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\484472.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\484472.exe
show_type:
0
|
success
|
1 |
0
|