| Time & API |
Arguments |
Status |
Return |
Repeated |
1619879174.266874
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xubzcq.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\xubzcq.exe
show_type:
0
|
success
|
1 |
0
|
1619879179.470874
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619879179.485874
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619879174.469999
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xubzcq.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\xubzcq.exe
show_type:
0
|
success
|
1 |
0
|
1619879195.876499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\514759.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\514759.exe
show_type:
0
|
success
|
1 |
0
|
1619879198.907499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\384616.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\384616.exe
show_type:
0
|
success
|
1 |
0
|
1619879201.938499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162240.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162240.exe
show_type:
0
|
success
|
1 |
0
|
1619879204.985499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\141874.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\141874.exe
show_type:
0
|
success
|
1 |
0
|
1619879208.016499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\164152.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\164152.exe
show_type:
0
|
success
|
1 |
0
|
1619879211.266499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\962586.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\962586.exe
show_type:
0
|
success
|
1 |
0
|
1619879214.329499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\293917.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\293917.exe
show_type:
0
|
success
|
1 |
0
|
1619879217.532499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750714.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750714.exe
show_type:
0
|
success
|
1 |
0
|
1619879220.673499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\633588.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\633588.exe
show_type:
0
|
success
|
1 |
0
|
1619879224.360499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\480750.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\480750.exe
show_type:
0
|
success
|
1 |
0
|
1619879227.454499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\620116.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\620116.exe
show_type:
0
|
success
|
1 |
0
|
1619879230.516499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\910820.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\910820.exe
show_type:
0
|
success
|
1 |
0
|
1619879233.579499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\146702.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\146702.exe
show_type:
0
|
success
|
1 |
0
|
1619879236.657499
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\389068.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\389068.exe
show_type:
0
|
success
|
1 |
0
|
1619879196.032751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\514759.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\514759.exe
show_type:
0
|
success
|
1 |
0
|
1619879199.062999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\384616.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\384616.exe
show_type:
0
|
success
|
1 |
0
|
1619879202.095249
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162240.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\162240.exe
show_type:
0
|
success
|
1 |
0
|
1619879205.141124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\141874.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\141874.exe
show_type:
0
|
success
|
1 |
0
|
1619879208.173374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\164152.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\164152.exe
show_type:
0
|
success
|
1 |
0
|
1619879211.438374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\962586.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\962586.exe
show_type:
0
|
success
|
1 |
0
|
1619879214.548874
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\293917.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\293917.exe
show_type:
0
|
success
|
1 |
0
|
1619879217.906999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750714.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\750714.exe
show_type:
0
|
success
|
1 |
0
|
1619879220.923626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\633588.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\633588.exe
show_type:
0
|
success
|
1 |
0
|
1619879224.595124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\480750.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\480750.exe
show_type:
0
|
success
|
1 |
0
|
1619879227.720874
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\620116.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\620116.exe
show_type:
0
|
success
|
1 |
0
|
1619879230.766374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\910820.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\910820.exe
show_type:
0
|
success
|
1 |
0
|
1619879233.766874
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\146702.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\146702.exe
show_type:
0
|
success
|
1 |
0
|