epName
|
ATTRIBUTE
|
VALUE
|
CONTEXT
|
CONTEXT_DATA
|
NOTES
|
|
=========================
|
=========================
|
=========================
|
=========================
|
=========================
|
|
OPERATING SYSTEM
|
Microsoft Windows 7 Ultimate
|
VERSION
|
6.1.7601
|
INSTALLED ON: 2016 09 12 15:40
|
|
IP-ADDRESS
|
192.168.100.143
|
MAC ADDRESS
|
00:50:56:2a:3a:13
|
DHCP SERVER: 192.168.100.254
|
|
IP-ADDRESS
|
fe80::100:7f:fffe
|
MAC ADDRESS
|
00:00:00:00:00:00:00:e0
|
DHCP SERVER:
|
|
HARD DISK
|
C:
|
SIZE
|
60.00(GB)
|
61.33% Free
|
|
CPU/MEMORY
|
Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz
|
MEMORY
|
3.00(GB)
|
VENDOR: VMware, Inc. MODEL: VMware Virtual Platform
|
|
UP TIME
|
3 days, 13 hours 18 minutes
|
BOOT MODE
|
|
|
|
PROCESS COUNT BY USER
|
SYSTEM
|
ACTIVE PROCESS COUNT
|
39
|
USER TYPE: special UID: 18 GID: 18
|
|
PROCESS COUNT BY USER
|
LOCAL SERVICE
|
ACTIVE PROCESS COUNT
|
15
|
USER TYPE: special UID: 19 GID: 19
|
|
PROCESS COUNT BY USER
|
NETWORK SERVICE
|
ACTIVE PROCESS COUNT
|
5
|
USER TYPE: special UID: 20 GID: 20
|
|
SUSPECT PUA
|
C:\Windows\System32\dllhost.exe
|
PUA SCORE
|
41
|
SHA256: f7ad4b09afb301ce46df695b22114331a57d52e6d4163ff74787bf68ccf44c78
|
|
SUSPECT PUA
|
C:\Program Files\Windows Media Player\wmpnetwk.exe
|
PUA SCORE
|
38
|
SHA256: 6c67dcb007c3cdf2eb0bbf5fd89c32cd7800c20f7166872f8c387be262c5cd21
|
|
SUSPECT PUA
|
C:\Windows\System32\autochk.exe
|
PUA SCORE
|
38
|
SHA256: 2e035366e9a1a26fb15f1e4857056e6ad7932bce8cc68bb4b655609f424d2756
|
|
SUSPECT PUA
|
C:\Windows\System32\csrss.exe
|
PUA SCORE
|
38
|
SHA256: f9112b88fec5ef10a7aedf88dcee61956d1fcde7cb42197216e8265578713786
|
|
SUSPECT PUA
|
C:\Windows\System32\conhost.exe
|
PUA SCORE
|
37
|
SHA256: 248d1591b39e6fbbf8ed081f9c0ffe99e76f2df180eb7371dcf531d9a58e4546
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding SOPHOS PID: 1484:132482013107543154
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding SOPHOS PID: 5572:132482013534837594
|
|
=========================
|
=========================
|
=========================
|
=========================
|
=========================
|
|
OPERATING SYSTEM
|
Microsoft Windows 7 Ultimate
|
VERSION
|
6.1.7601
|
INSTALLED ON: 2016 09 12 15:40
|
|
IP-ADDRESS
|
192.168.100.183
|
MAC ADDRESS
|
00:50:56:25:94:3c
|
DHCP SERVER: 192.168.100.254
|
|
IP-ADDRESS
|
fe80::100:7f:fffe
|
MAC ADDRESS
|
00:00:00:00:00:00:00:e0
|
DHCP SERVER:
|
|
HARD DISK
|
C:
|
SIZE
|
60.00(GB)
|
60.67% Free
|
|
CPU/MEMORY
|
Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz
|
MEMORY
|
3.00(GB)
|
VENDOR: VMware, Inc. MODEL: VMware Virtual Platform
|
|
UP TIME
|
3 days, 13 hours 18 minutes
|
BOOT MODE
|
|
|
|
PROCESS COUNT BY USER
|
SYSTEM
|
ACTIVE PROCESS COUNT
|
38
|
USER TYPE: special UID: 18 GID: 18
|
|
PROCESS COUNT BY USER
|
LOCAL SERVICE
|
ACTIVE PROCESS COUNT
|
15
|
USER TYPE: special UID: 19 GID: 19
|
|
PROCESS COUNT BY USER
|
NETWORK SERVICE
|
ACTIVE PROCESS COUNT
|
6
|
USER TYPE: special UID: 20 GID: 20
|
|
PROCESS COUNT BY USER
|
test
|
ACTIVE PROCESS COUNT
|
10
|
USER TYPE: local UID: 1002 GID: 513
|
|
SUSPECT PUA
|
C:\Windows\System32\dllhost.exe
|
PUA SCORE
|
41
|
SHA256: f7ad4b09afb301ce46df695b22114331a57d52e6d4163ff74787bf68ccf44c78
|
|
SUSPECT PUA
|
C:\Program Files\Windows Media Player\wmpnetwk.exe
|
PUA SCORE
|
38
|
SHA256: 6c67dcb007c3cdf2eb0bbf5fd89c32cd7800c20f7166872f8c387be262c5cd21
|
|
SUSPECT PUA
|
C:\Windows\System32\autochk.exe
|
PUA SCORE
|
38
|
SHA256: 2e035366e9a1a26fb15f1e4857056e6ad7932bce8cc68bb4b655609f424d2756
|
|
SUSPECT PUA
|
C:\Windows\System32\csrss.exe
|
PUA SCORE
|
38
|
SHA256: f9112b88fec5ef10a7aedf88dcee61956d1fcde7cb42197216e8265578713786
|
|
SUSPECT PUA
|
C:\Windows\System32\conhost.exe
|
PUA SCORE
|
37
|
SHA256: 248d1591b39e6fbbf8ed081f9c0ffe99e76f2df180eb7371dcf531d9a58e4546
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\PerfLogs\SophosSetup.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:25 CREATING PROCESS SPID: 6428:132485084615493431
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\test\AppData\Local\Temp\sfl-86709b40\Setup.exe
|
CREATING PROCESS NAME
|
SophosSetup.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:38 CREATING PROCESS SPID: 6528:132485085981990104
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Program Files\Sophos\CloudInstaller\extract_cache\SophosSetup_Stage2.exe
|
CREATING PROCESS NAME
|
Setup.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:55 CREATING PROCESS SPID: 7236:132485085984642109
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\PerfLogs\SophosSetup.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:25 CREATING PROCESS SPID: 6428:132485084615493431
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\test\AppData\Local\Temp\sfl-86709b40\Setup.exe
|
CREATING PROCESS NAME
|
SophosSetup.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:38 CREATING PROCESS SPID: 6528:132485085981990104
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Program Files\Sophos\CloudInstaller\extract_cache\SophosSetup_Stage2.exe
|
CREATING PROCESS NAME
|
Setup.exe
|
CREATED BY: test CREATED ON: 2020-10-30 05:16:55 CREATING PROCESS SPID: 7236:132485085984642109
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding SOPHOS PID: 5276:132482013226331772
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: rundll32 C:\Windows\system32\generaltel.dll,RunInUserCxt yr1WC98xYUeiFhBC.1 Census SOPHOS PID: 4360:132482840457734512
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: rundll32 C:\Windows\system32\generaltel.dll,RunInUserCxt OUqtUY43BU2WrqCJ.1 Census SOPHOS PID: 6040:132485858646823219
|
|
LIVE OFF LAND TOOL USE (Last 7 days)
|
rundll32.exe
|
RUN BY USER
|
test
|
COMMAND LINE: rundll32 C:\Windows\system32\generaltel.dll,RunInUserCxt iW71dRP6jEWqAl8a.1 Census SOPHOS PID: 6776:132486737379512842
|
|
=========================
|
=========================
|
=========================
|
=========================
|
=========================
|
|
OPERATING SYSTEM
|
Microsoft Windows 10 Pro
|
VERSION
|
10.0.19041
|
INSTALLED ON: 2020 06 10 10:25
|
|
IP-ADDRESS
|
fe80::3837:20c:2ac5:235
|
MAC ADDRESS
|
6e:ea:1d:c1:aa:55
|
DHCP SERVER:
|
|
IP-ADDRESS
|
169.254.2.53
|
MAC ADDRESS
|
6e:ea:1d:c1:aa:55
|
DHCP SERVER:
|
|
IP-ADDRESS
|
fe80::3046:a74:92c1:4245
|
MAC ADDRESS
|
00:50:56:c0:00:0a
|
DHCP SERVER:
|
|
IP-ADDRESS
|
172.16.16.1
|
MAC ADDRESS
|
00:50:56:c0:00:0a
|
DHCP SERVER:
|
|
IP-ADDRESS
|
fe80::cff:dcd7:bb9e:34ed
|
MAC ADDRESS
|
00:50:56:c0:00:08
|
DHCP SERVER:
|
|
IP-ADDRESS
|
192.168.100.1
|
MAC ADDRESS
|
00:50:56:c0:00:08
|
DHCP SERVER:
|
|
IP-ADDRESS
|
fe80::f101:efed:1c0:a21e
|
MAC ADDRESS
|
00:50:56:c0:00:10
|
DHCP SERVER:
|
|
IP-ADDRESS
|
10.50.50.1
|
MAC ADDRESS
|
00:50:56:c0:00:10
|
DHCP SERVER:
|
|
IP-ADDRESS
|
fe80::fc6e:5922:21d5:be56
|
MAC ADDRESS
|
5c:ea:1d:c1:aa:55
|
DHCP SERVER: 192.168.1.1
|
|
IP-ADDRESS
|
192.168.1.173
|
MAC ADDRESS
|
5c:ea:1d:c1:aa:55
|
DHCP SERVER: 192.168.1.1
|
|
HARD DISK
|
C:
|
SIZE
|
952.14(GB)
|
10.61% Free
|
|
CPU/MEMORY
|
Intel(R) Core(TM) i7-7700HQ CPU @ 2.80GHz
|
MEMORY
|
63.83(GB)
|
VENDOR: Dell Inc. MODEL: Precision 7720
|
|
UP TIME
|
4 days, 9 hours 28 minutes
|
BOOT MODE
|
|
|
|
PROCESS COUNT BY USER
|
SYSTEM
|
ACTIVE PROCESS COUNT
|
121
|
USER TYPE: special UID: 18 GID: 18
|
|
PROCESS COUNT BY USER
|
LOCAL SERVICE
|
ACTIVE PROCESS COUNT
|
44
|
USER TYPE: special UID: 19 GID: 19
|
|
PROCESS COUNT BY USER
|
NETWORK SERVICE
|
ACTIVE PROCESS COUNT
|
10
|
USER TYPE: special UID: 20 GID: 20
|
|
PROCESS COUNT BY USER
|
Admin
|
ACTIVE PROCESS COUNT
|
92
|
USER TYPE: local UID: 1001 GID: 513
|
|
SUSPECT PUA
|
C:\Windows\System32\services.exe
|
PUA SCORE
|
37
|
SHA256: 2400ad6ba8b57ee28972db12e39f5546ceff1854ee1013c22ac756ed64dc353d
|
|
SUSPECT PUA
|
C:\Windows\System32\sc.exe
|
PUA SCORE
|
35
|
SHA256: 41f067c3a11b02fe39947f9eba68ae5c7cb5bd1872a6009a4cd1506554a9aba9
|
|
SUSPECT PUA
|
C:\Windows\System32\dxgiadaptercache.exe
|
PUA SCORE
|
32
|
SHA256: 7ee345476d996e05e7d7519e0639abbc6d23011b5c38bfdcc63ad89d1352270a
|
|
SUSPECT PUA
|
C:\Windows\System32\MusNotification.exe
|
PUA SCORE
|
32
|
SHA256: 819fc501339911469bd79bc485101d18dd5cedc2de6f9e3fb112fcd68bf382fb
|
|
SUSPECT PUA
|
C:\Windows\System32\wevtutil.exe
|
PUA SCORE
|
31
|
SHA256: 4a727688b939e08c26064ea08dcff29b3d4608d28820874030524f79b4b1cca8
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\65B44228-124C-4448-8511-EC7DD31EB9C3\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-25 21:12:49 CREATING PROCESS SPID: 2540:132481339637393306
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\725421a842714d28b845ff146ca42cb3\vs_setup_bootstrapper.exe
|
CREATING PROCESS NAME
|
devenv.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:39 CREATING PROCESS SPID: 7288:132481829693627065
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\khuriej3.exe
|
CREATING PROCESS NAME
|
devenv.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:39 CREATING PROCESS SPID: 7288:132481829693627065
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\1bcb0a70932b47a7af669cf0f2736e7b\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
|
CREATING PROCESS NAME
|
vs_setup_bootstrapper.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:42 CREATING PROCESS SPID: 832:132481830398886053
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\DEBRAIN.EXE
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:31:16 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\$Recycle.Bin\S-1-5-21-1046890641-3398658149-2418694993-1001\$I405YYF.EXE
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:32:01 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\Vcffipzmnipbxzdl.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:32:43 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\68CF2614-4430-4EF2-B5F8-C35FD3476C02\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-27 18:29:20 CREATING PROCESS SPID: 7384:132482969563973777
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\099D4F03-45D3-4D1F-A604-EF35E8919D2A\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-28 17:45:54 CREATING PROCESS SPID: 15472:132483807534144736
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
|
CREATING PROCESS NAME
|
OneDriveStandaloneUpdater.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:38 CREATING PROCESS SPID: 20452:132484561460515708
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileCoAuth.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileSyncConfig.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileSyncHelper.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\MicrosoftListSync.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\MicrosoftListSyncNativeMessagingClient.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveUpdaterService.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:45 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveSetup.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0006\{4200586B-9416-44E2-A433-A21AC7F38159}_OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0006\{38E04DBA-5646-42A1-82C9-8EC5088FBE03}_OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\67B37BA3-9BCE-4C52-B8D8-902E8DFF4746\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 17:11:29 CREATING PROCESS SPID: 18344:132484650868004878
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\A7BDE2FC-04DA-4264-A2D8-CCB8D5CCB190\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 18:21:26 CREATING PROCESS SPID: 15988:132484692856020961
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\$Recycle.Bin\S-1-5-21-1046890641-3398658149-2418694993-1001\$IUEC255.exe
|
CREATING PROCESS NAME
|
dllhost.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 04:45:09 CREATING PROCESS SPID: 16184:132485058970101352
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\vmware-Admin\VMwareDnD\138c3d80\RansomGen.exe
|
CREATING PROCESS NAME
|
vmware-vmx.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 04:47:27 CREATING PROCESS SPID: 13508:132483644611850967
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\1BF91BE7-8C11-4375-8F62-EDDD27A755EE\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 16:25:29 CREATING PROCESS SPID: 19672:132485487281094174
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\9175C3CA-FC9C-4D94-AFAF-5B26F190559C\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-31 15:07:11 CREATING PROCESS SPID: 21928:132486304305415025
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\3F5382CB-75B7-4E38-A5D5-1FB1F7F386BB\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-11-01 15:07:10 CREATING PROCESS SPID: 8996:132487168297906502
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\725421a842714d28b845ff146ca42cb3\vs_setup_bootstrapper.exe
|
CREATING PROCESS NAME
|
devenv.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:39 CREATING PROCESS SPID: 7288:132481829693627065
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\DEBRAIN.EXE
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 1989-11-29 01:10:36 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\PerfLogs\sample IOC hunting query for Carbanak and Fin7.exe
|
CREATING PROCESS NAME
|
dllhost.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 12:59:37 CREATING PROCESS SPID: 16184:132485058970101352
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\PerfLogs\TEST_CONFIRM WILDCARD MATCH.exe
|
CREATING PROCESS NAME
|
dllhost.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 12:59:37 CREATING PROCESS SPID: 16184:132485058970101352
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\vmware-Admin\VMwareDnD\138c3d80\RansomGen.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-01-28 15:08:50 CREATING PROCESS SPID: 5016:132483568139498111
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\RansomGen.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-01-28 15:08:50 CREATING PROCESS SPID: 5016:132483568139498111
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\PerfLogs\RansomGen.exe
|
CREATING PROCESS NAME
|
dllhost.exe
|
CREATED BY: Admin CREATED ON: 2020-01-28 15:08:50 CREATING PROCESS SPID: 16184:132485058970101352
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\65B44228-124C-4448-8511-EC7DD31EB9C3\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-25 21:12:49 CREATING PROCESS SPID: 2540:132481339637393306
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\khuriej3.exe
|
CREATING PROCESS NAME
|
devenv.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:39 CREATING PROCESS SPID: 7288:132481829693627065
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\725421a842714d28b845ff146ca42cb3\vs_setup_bootstrapper.exe
|
CREATING PROCESS NAME
|
devenv.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 10:50:39 CREATING PROCESS SPID: 7288:132481829693627065
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\1bcb0a70932b47a7af669cf0f2736e7b\vs_bootstrapper_d15\vs_setup_bootstrapper.exe
|
CREATING PROCESS NAME
|
vs_setup_bootstrapper.exe
|
CREATED BY: Admin CREATED ON: 2020-08-27 02:56:24 CREATING PROCESS SPID: 832:132481830398886053
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\DEBRAIN.EXE
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:31:16 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\$Recycle.Bin\S-1-5-21-1046890641-3398658149-2418694993-1001\$I405YYF.EXE
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:32:01 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\Desktop\Vcffipzmnipbxzdl.exe
|
CREATING PROCESS NAME
|
explorer.exe
|
CREATED BY: Admin CREATED ON: 2020-10-26 19:32:43 CREATING PROCESS SPID: 4448:132482138074149110
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\68CF2614-4430-4EF2-B5F8-C35FD3476C02\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-27 18:29:20 CREATING PROCESS SPID: 7384:132482969563973777
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\099D4F03-45D3-4D1F-A604-EF35E8919D2A\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-28 17:45:54 CREATING PROCESS SPID: 15472:132483807534144736
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\OneDriveSetup.exe
|
CREATING PROCESS NAME
|
OneDriveStandaloneUpdater.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:38 CREATING PROCESS SPID: 20452:132484561460515708
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileCoAuth.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileSyncConfig.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\FileSyncHelper.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\MicrosoftListSync.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\MicrosoftListSyncNativeMessagingClient.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:44 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveUpdaterService.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:45 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0008\OneDriveSetup.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0006\{4200586B-9416-44E2-A433-A21AC7F38159}_OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\OneDrive.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\20.169.0823.0006\{38E04DBA-5646-42A1-82C9-8EC5088FBE03}_OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
|
CREATING PROCESS NAME
|
OneDriveSetup.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 14:42:52 CREATING PROCESS SPID: 13748:132484561623029376
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\67B37BA3-9BCE-4C52-B8D8-902E8DFF4746\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 17:11:29 CREATING PROCESS SPID: 18344:132484650868004878
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\A7BDE2FC-04DA-4264-A2D8-CCB8D5CCB190\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-29 18:21:26 CREATING PROCESS SPID: 15988:132484692856020961
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\$Recycle.Bin\S-1-5-21-1046890641-3398658149-2418694993-1001\$IUEC255.exe
|
CREATING PROCESS NAME
|
dllhost.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 04:45:09 CREATING PROCESS SPID: 16184:132485058970101352
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\vmware-Admin\VMwareDnD\138c3d80\RansomGen.exe
|
CREATING PROCESS NAME
|
vmware-vmx.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 04:47:27 CREATING PROCESS SPID: 13508:132483644611850967
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\1BF91BE7-8C11-4375-8F62-EDDD27A755EE\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-30 16:25:29 CREATING PROCESS SPID: 19672:132485487281094174
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\9175C3CA-FC9C-4D94-AFAF-5B26F190559C\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-10-31 15:07:11 CREATING PROCESS SPID: 21928:132486304305415025
|
|
NEW USER INSTALLED EXECUTABLE (last 7 days)
|
C:\Users\kacke\AppData\Local\Temp\3F5382CB-75B7-4E38-A5D5-1FB1F7F386BB\DismHost.exe
|
CREATING PROCESS NAME
|
cleanmgr.exe
|
CREATED BY: Admin CREATED ON: 2020-11-01 15:07:10 CREATING PROCESS SPID: 8996:132487168297906502
|