| Time & API |
Arguments |
Status |
Return |
Repeated |
1619880756.333501
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\wdnioy.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\wdnioy.exe
show_type:
0
|
success
|
1 |
0
|
1619880761.036501
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619880761.036501
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619880756.584251
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\wdnioy.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\wdnioy.exe
show_type:
0
|
success
|
1 |
0
|
1619880777.896626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\948302.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\948302.exe
show_type:
0
|
success
|
1 |
0
|
1619880780.927626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\773748.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\773748.exe
show_type:
0
|
success
|
1 |
0
|
1619880784.052626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\551373.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\551373.exe
show_type:
0
|
success
|
1 |
0
|
1619880787.115626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\055803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\055803.exe
show_type:
0
|
success
|
1 |
0
|
1619880790.146626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\442601.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\442601.exe
show_type:
0
|
success
|
1 |
0
|
1619880793.177626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\220235.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\220235.exe
show_type:
0
|
success
|
1 |
0
|
1619880796.349626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\098860.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\098860.exe
show_type:
0
|
success
|
1 |
0
|
1619880799.583626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\079747.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\079747.exe
show_type:
0
|
success
|
1 |
0
|
1619880802.646626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\136437.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\136437.exe
show_type:
0
|
success
|
1 |
0
|
1619880805.771626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\423235.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\423235.exe
show_type:
0
|
success
|
1 |
0
|
1619880808.833626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\125764.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\125764.exe
show_type:
0
|
success
|
1 |
0
|
1619880811.990626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\028294.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\028294.exe
show_type:
0
|
success
|
1 |
0
|
1619880815.130626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\919089.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\919089.exe
show_type:
0
|
success
|
1 |
0
|
1619880818.208626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\372702.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\372702.exe
show_type:
0
|
success
|
1 |
0
|
1619880778.069126
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\948302.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\948302.exe
show_type:
0
|
success
|
1 |
0
|
1619880781.083374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\773748.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\773748.exe
show_type:
0
|
success
|
1 |
0
|
1619880784.208374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\551373.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\551373.exe
show_type:
0
|
success
|
1 |
0
|
1619880787.271876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\055803.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\055803.exe
show_type:
0
|
success
|
1 |
0
|
1619880790.303126
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\442601.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\442601.exe
show_type:
0
|
success
|
1 |
0
|
1619880793.349374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\220235.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\220235.exe
show_type:
0
|
success
|
1 |
0
|
1619880796.647126
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\098860.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\098860.exe
show_type:
0
|
success
|
1 |
0
|
1619880800.006001
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\079747.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\079747.exe
show_type:
0
|
success
|
1 |
0
|
1619880802.849751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\136437.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\136437.exe
show_type:
0
|
success
|
1 |
0
|
1619880805.944126
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\423235.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\423235.exe
show_type:
0
|
success
|
1 |
0
|
1619880809.036626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\125764.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\125764.exe
show_type:
0
|
success
|
1 |
0
|
1619880812.208751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\028294.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\028294.exe
show_type:
0
|
success
|
1 |
0
|
1619880815.459126
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\919089.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\919089.exe
show_type:
0
|
success
|
1 |
0
|
1619880818.740876
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\372702.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\372702.exe
show_type:
0
|
success
|
1 |
0
|