| Time & API |
Arguments |
Status |
Return |
Repeated |
1619910850.129074
ShellExecuteExW
|
parameters:
/jscxyxztjkl
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ydmyxc.exe
filepath_r:
C:\Users\ADMINI~1.OSK\AppData\Local\Temp\\ydmyxc.exe
show_type:
0
|
success
|
1 |
0
|
1619910854.489074
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619910854.489074
ShellExecuteExW
|
parameters:
filepath:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
filepath_r:
http://hao.360.cn/?src=lm&ls=n6abbbb598c
show_type:
0
|
success
|
1 |
0
|
1619920229.693999
ShellExecuteExW
|
parameters:
/jsjczxztcq
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ydmyxc.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ydmyxc.exe
show_type:
0
|
success
|
1 |
0
|
1619920239.710626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\972665.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\972665.exe
show_type:
0
|
success
|
1 |
0
|
1619920243.991626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\099125.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\099125.exe
show_type:
0
|
success
|
1 |
0
|
1619920247.491626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\310999.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\310999.exe
show_type:
0
|
success
|
1 |
0
|
1619920251.147626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\396742.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\396742.exe
show_type:
0
|
success
|
1 |
0
|
1619920255.756626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\413282.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\413282.exe
show_type:
0
|
success
|
1 |
0
|
1619920260.131626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\361356.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\361356.exe
show_type:
0
|
success
|
1 |
0
|
1619920263.803626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\137802.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\137802.exe
show_type:
0
|
success
|
1 |
0
|
1619920267.428626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\054363.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\054363.exe
show_type:
0
|
success
|
1 |
0
|
1619920271.553626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\768907.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\768907.exe
show_type:
0
|
success
|
1 |
0
|
1619920274.928626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\645039.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\645039.exe
show_type:
0
|
success
|
1 |
0
|
1619920279.663626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\000894.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\000894.exe
show_type:
0
|
success
|
1 |
0
|
1619920282.897626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\303697.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\303697.exe
show_type:
0
|
success
|
1 |
0
|
1619920286.022626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386371.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386371.exe
show_type:
0
|
success
|
1 |
0
|
1619920290.147626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\981806.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\981806.exe
show_type:
0
|
success
|
1 |
0
|
1619920293.631626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831929.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831929.exe
show_type:
0
|
success
|
1 |
0
|
1619920297.756626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541958.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541958.exe
show_type:
0
|
success
|
1 |
0
|
1619920302.163626
ShellExecuteExW
|
parameters:
/Shorttailedrestart
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\566626.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\566626.exe
show_type:
0
|
success
|
1 |
0
|
1619920240.069751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\972665.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\972665.exe
show_type:
0
|
success
|
1 |
0
|
1619920244.428374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\099125.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\099125.exe
show_type:
0
|
success
|
1 |
0
|
1619920247.741374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\310999.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\310999.exe
show_type:
0
|
success
|
1 |
0
|
1619920251.647124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\396742.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\396742.exe
show_type:
0
|
success
|
1 |
0
|
1619920256.630999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\413282.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\413282.exe
show_type:
0
|
success
|
1 |
0
|
1619920262.366124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\361356.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\361356.exe
show_type:
0
|
success
|
1 |
0
|
1619920266.694124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\137802.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\137802.exe
show_type:
0
|
success
|
1 |
0
|
1619920270.147374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\054363.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\054363.exe
show_type:
0
|
success
|
1 |
0
|
1619920273.897751
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\768907.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\768907.exe
show_type:
0
|
success
|
1 |
0
|
1619920276.772374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\645039.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\645039.exe
show_type:
0
|
success
|
1 |
0
|
1619920280.038124
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\000894.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\000894.exe
show_type:
0
|
success
|
1 |
0
|
1619920283.193999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\303697.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\303697.exe
show_type:
0
|
success
|
1 |
0
|
1619920286.412999
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386371.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\386371.exe
show_type:
0
|
success
|
1 |
0
|
1619920290.741626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\981806.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\981806.exe
show_type:
0
|
success
|
1 |
0
|
1619920294.178374
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831929.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\831929.exe
show_type:
0
|
success
|
1 |
0
|
1619920298.178501
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541958.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\541958.exe
show_type:
0
|
success
|
1 |
0
|
1619920304.069626
ShellExecuteExW
|
parameters:
filepath:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\566626.exe
filepath_r:
C:\Users\Administrator.Oskar-PC\AppData\Roaming\Download\566626.exe
show_type:
0
|
success
|
1 |
0
|