Report #11149 check_circle

  • Creation Date: Sept. 8, 2020, 1:40 a.m.
  • Last Update: Sept. 8, 2020, 1:44 a.m.
  • File: 048
  • Results:
Binary
DLL
False cancel
Size
1.17MB
trid
61.8% Win32 Executable MS Visual C++
13.0% Win32 Dynamic Link Library
8.9% Win32 Executable
4.1% Win16/32 Executable Delphi generic
4.0% OS/2 Executable
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
8ba8a22ba30e2dd2eb69bb9f50841ee3
sha1
2f0046fc80d6aad6464f1c064873aa7becd540cd
crc32
0xfbe836f2
sha224
311caedd26dcb35090b4ef7fa176b1c9e62755d17cff6dcb88ba97ae
sha256
2923b0d410dc2b3827f3c66ed06aac9247f7038a0e95a6328bc7d1c8da4c570b
sha384
69e1016fd09a03107fcf99f43754d10aff308983510887423c21deef637e3f246d747d49f389f9dab2f87201c96abe38
sha512
b66aa465d4c90277d499d39f16464d9895c3a7cb8de3ccfd2d619da2331859d91275727d7794509f3b3080afef17e13c55e18414e6e01ab0e1e4b74e7df05954
ssdeep
3072:0jY9xJ5k3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3v3veX:v9DeCBa1kf0A
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
domain, contentis_base64, Check_OutputDebugStringA_iat, HasDigitalSignature, screenshot, url, win_token, win_mutex, win_registry, Microsoft_Visual_Cpp_v50v60_MFC, HasOverlay, win_files_operation, IsPE32, anti_dbg, IsWindowsGUI, IP

Suspicious
True check_circle

Strings
List
,https://www.example.com/my_product/info.html0
siy.al
wmlaunch.exe
wmlaunch.exe
name="Microsoft.Windows.MediaPlayer.WMLaunch"
co0.ec:
$11w.ro
COMCTL32.dll
Cla/eHw.dlk
RinterfacE\{b196b287-bab4-101a-b69c-00aa00341d07}
`E>8ra%8Fi"iNa
0d]%e
*tmg%naT_s
ro%Edd
<description>Windows Media Player Launcher</description>
]AuzgRu`Cmd
0aTCpaEMUAEJ
<requestedPrivileges>
Windows Media Player Launcher
GetProcAddress
ExitProcess
CreateEventW
SetWinEventHook
DDPIgVncJv
GetForegroundWindow
SuspendThread
CreateProcessW
CreateProcessA
TerminateProcess
OpenProcessToken
DeviceIoControl
ShellExecuteExW
VirtualAlloc
CoCreateInstance
VirtualAlloc
MapViewOfFileEx
MapViewOfFile
VirtualProtect
ControlService
CreateDirectoryW
GetModuleHandleA
RegOpenKeyW
DeleteFileW
RegCreateKeyExW
CreateFileMappingA
RegQueryValueExW
LoadLibraryA
RemoveDirectoryA
RegDeleteValueW
OpenServiceW
LoadResource
CreateMutexW
OpenSCManagerW
StartServiceW
QueryPerformanceCounter
RegOpenKeyExA
DeleteService
GetModuleFileNameA
RemoveDirectoryW
GetModuleFileNameW
HeapCreate
SetFilePointer
RegQueryValueExA
RegOpenKeyExW
CreateDirectoryA
FreeLibrary
LoadLibraryExW
CopyFileW
FindNextFileW
GetModuleHandleW
RegSetValueExW
FindFirstFileW
WriteFile
CreateFileW
LoadLibraryW
CreateFileA
RegDeleteKeyW
MoveFileExW
CreateFileMappingW
ReadFile
Microsoft Corporation. All rights reserved.
GetTickCount
he wYBbqVS
Sleep
GetDC
<requestedExecutionLevel
GetConsoleOutputCP
GetCPInfo
GetProcessHeap
EN3D$N5E
version="5.1.0.0"
ap!6tPe
1"12g-roeZss
q$11g.rouYss
__E)t_'4p_
Z2WaPra_es
be6vun&kn
<FibaPc5
"10w9et
"10w9et

Foremost
Matches
0.exe, 1 MB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: True check_circle
Suspicious: https://www.example.com/my_product/info.html0
hasAllowed: False cancel
hasSuspicious: True check_circle

Files
Allowed: ADVAPI32.dll, ole32.dll, SHELL32.dll, COMCTL32.dll, COMDLG32.dll, GDI32.dll, USER32.dll, KERNEL32.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 802304
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 1256702
Suspicous: False cancel

Sections
Allowed: .text, .data, .rdata8, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 4
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 4
Linker
Version: 2.50
Suspicious: False cancel
Subsystem
Version: 4.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 419200
Suspicious: False cancel

Anomalies
Anomalies
hasAnomalies: False cancel

Libraries
Allowed: advapi32.dll, ole32.dll, shell32.dll, comctl32.dll, comdlg32.dll, gdi32.dll, user32.dll, kernel32.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2020-07-28 23:33:49
Future: False cancel

Compilation
Packed: False cancel
Missing: True check_circle
Packers
Compiled: False cancel
Compilers

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.data: 16
.text: 1

pushpopmath
.data: 22
.text: 1

garbagebytes
.data: 4
.text: 1

programcontrolflowchange
.data: 4
.text: 1

cpuinstructionsresultscomparison
.data: 3

AVclass
bobik
1
VirusTotal
md5
8ba8a22ba30e2dd2eb69bb9f50841ee3
sha1
2f0046fc80d6aad6464f1c064873aa7becd540cd
SCANS
AVG
result: Win32:DangerousSig [Trj]
update: 20200806
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20200805
version: 2.7.2019.1
detected: False cancel

MAX
result: malware (ai score=89)
update: 20200806
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20200804
version: 6.56
detected: True check_circle

Bkav
result: W32.AIDetectVM.malware2
update: 20200806
version: 1.3.0.9899
detected: True check_circle

K7GW
result: Trojan ( 005652be1 )
update: 20200806
version: 11.128.34909
detected: True check_circle

ALYac
result: Gen:Variant.Razy.725518
update: 20200806
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:DangerousSig [Trj]
update: 20200806
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Kryptik.kdxer
update: 20200806
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cynet
result: Malicious (score: 85)
update: 20200806
version: 4.0.0.24
detected: True check_circle

Cyren
result: W32/Trojan.MSQE-8110
update: 20200806
version: 6.3.0.2
detected: True check_circle

DrWeb
update: 20200806
version: 7.0.46.3050
detected: False cancel

GData
result: Gen:Variant.Razy.725518
update: 20200806
version: A:25.26487B:27.19700
detected: True check_circle

Panda
result: Trj/GdSda.A
update: 20200805
version: 4.6.4.2
detected: True check_circle

VBA32
result: BScope.Trojan.Inject
update: 20200805
version: 4.4.1
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20200806
version: 85730
detected: True check_circle

Zoner
update: 20200806
version: 0.0.0.0
detected: False cancel

ClamAV
update: 20200805
version: 0.102.4.0
detected: False cancel

Comodo
update: 20200728
version: 32668
detected: False cancel

F-Prot
update: 20200806
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan-Spy.Agent
update: 20200805
version: 0.1.5.2
detected: True check_circle

McAfee
result: Packed-GBS!8BA8A22BA30E
update: 20200806
version: 6.0.6.653
detected: True check_circle

Rising
result: Trojan.Kryptik!1.C974 (CLOUD)
update: 20200806
version: 25.0.0.26
detected: True check_circle

Sophos
result: Mal/EncPk-APV
update: 20200806
version: 4.98.0
detected: True check_circle

Yandex
update: 20200707
version: 5.5.2.24
detected: False cancel

Zillya
result: Downloader.Deyma.Win32.166
update: 20200805
version: 2.0.0.4148
detected: True check_circle

Acronis
update: 20200603
version: 1.1.1.76
detected: False cancel

Alibaba
result: Trojan:Win32/Kryptik.a56dbe92
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
result: Trojan.Razy.DB120E
update: 20200806
version: 1.0.0.877
detected: True check_circle

Cylance
result: Unsafe
update: 20200806
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20200727
version: 4.0.6
detected: True check_circle

FireEye
result: Generic.mg.8ba8a22ba30e2dd2
update: 20200806
version: 32.36.1.0
detected: True check_circle

Sangfor
result: Malware
update: 20200423
version: 1.0
detected: True check_circle

TACHYON
update: 20200806
version: 2020-08-06.02
detected: False cancel

Tencent
result: Malware.Win32.Gencirc.11a9aac1
update: 20200806
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20200806
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20200806
version: 1.0.0.403
detected: False cancel

eGambit
update: 20200806
detected: False cancel

Ad-Aware
result: Gen:Variant.Razy.725518
update: 20200806
version: 3.0.5.370
detected: True check_circle

AegisLab
result: Trojan.Win32.Bobik.l!c
update: 20200806
version: 4.2
detected: True check_circle

Emsisoft
result: Gen:Variant.Razy.725518 (B)
update: 20200806
version: 2018.12.0.1641
detected: True check_circle

F-Secure
result: Trojan.TR/Kryptik.kdxer
update: 20200806
version: 12.0.86.52
detected: True check_circle

Fortinet
result: W32/Cridex.VHO!tr
update: 20200806
version: 6.2.142.0
detected: True check_circle

Invincea
result: heuristic
update: 20200502
version: 6.3.6.26157
detected: True check_circle

Jiangmin
result: TrojanDownloader.Deyma.qq
update: 20200806
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20200806
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20200806
version: 1.0
detected: True check_circle

Symantec
result: ML.Attribute.HighConfidence
update: 20200806
version: 1.11.0.0
detected: True check_circle

Trapmine
update: 20200727
version: 3.5.0.1023
detected: False cancel

AhnLab-V3
update: 20200806
version: 3.18.1.10026
detected: False cancel

Antiy-AVL
result: Trojan[Downloader]/Win32.Deyma
update: 20200806
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: Trojan-Spy.Win32.Bobik.ene
update: 20200806
version: 15.0.1.13
detected: True check_circle

Microsoft
result: Trojan:Win32/Cridex.AR!cert
update: 20200806
version: 1.1.17300.4
detected: True check_circle

Qihoo-360
result: Generic/HEUR/QVM20.1.E37E.Malware.Gen
update: 20200806
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: Trojan-Spy.Win32.Bobik.ene
update: 20200806
version: 1.0
detected: True check_circle

Cybereason
result: malicious.c80d6a
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win32/Kryptik.HFHM
update: 20200805
version: 21771
detected: True check_circle

TrendMicro
result: TROJ_GEN.R002C0PGT20
update: 20200806
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: Gen:Variant.Razy.725518
update: 20200806
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_100% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan ( 005652be1 )
update: 20200806
version: 11.128.34910
detected: True check_circle

SentinelOne
result: DFI - Malicious PE
update: 20200725
version: 4.4.0.0
detected: True check_circle

Avast-Mobile
update: 20200806
version: 200806-00
detected: False cancel

Malwarebytes
result: Spyware.PasswordStealer
update: 20200806
version: 3.6.4.335
detected: True check_circle

TotalDefense
update: 20200806
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Trojanspy.Bobik
update: 20200806
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.Bobik.hpqiwf
update: 20200806
version: 1.0.134.25119
detected: True check_circle

BitDefenderTheta
result: Gen:NN.ZexaF.34152.kr1@aCYR!zei
update: 20200805
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: Gen:Variant.Razy.725518
update: 20200806
version: 14.0.409.0
detected: True check_circle

SUPERAntiSpyware
update: 20200731
version: 5.6.0.1032
detected: False cancel

TrendMicro-HouseCall
result: TROJ_GEN.R002C0PGT20
update: 20200806
version: 10.0.0.1040
detected: True check_circle

total
72
sha256
2923b0d410dc2b3827f3c66ed06aac9247f7038a0e95a6328bc7d1c8da4c570b
scan_id
2923b0d410dc2b3827f3c66ed06aac9247f7038a0e95a6328bc7d1c8da4c570b-1596696221
resource
8ba8a22ba30e2dd2eb69bb9f50841ee3
positives
53
scan_date
2020-08-06 06:43:41
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\AVAST Software
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Avira
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Kaspersky Lab
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\ESET
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Panda Security
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Doctor Web
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\AVG
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\360TotalSecurity
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Bitdefender
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Norton
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Sophos
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\Comodo
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\programdata\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:42.762Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.762Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.762Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.778Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.778Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Read1480C:\malware.exeC:\malware.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe:Zone.Identifier
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe:Zone.Identifier
8/9/2020 - 0:45:42.903Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:42.903Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.75Write1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Read1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\programdata\1321ba6d1f\ui\SwDRM.dll
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Unknown1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Read1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Read1480C:\malware.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\Prefetch\BDIF.EXE-3877C1E9.pf
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\System32\wow64log.dll
8/9/2020 - 0:45:43.262Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:45:43.262Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\bdif.exe.Local
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
8/9/2020 - 0:45:43.278Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
8/9/2020 - 0:45:43.278Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:45:43.293Unknown1480C:\malware.exeC:\Windows
8/9/2020 - 0:45:43.293Unknown1480C:\malware.exeC:\Monitor
8/9/2020 - 0:45:43.293Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
8/9/2020 - 0:45:43.293Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\4350ijy30u945j9f
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\4350ijy30u945j9f
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\Fonts\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\system\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wbem\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WindowsPowerShell\v1.0\zZoddUUrBc
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\Fonts\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\system\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wbem\jsMbd Trk
8/9/2020 - 0:45:43.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WindowsPowerShell\v1.0\jsMbd Trk
8/9/2020 - 0:45:43.325Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:45:43.372Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\WSOCK32.DLL
8/9/2020 - 0:45:43.372Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wsock32.dll
8/9/2020 - 0:45:43.372Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wsock32.dll
8/9/2020 - 0:45:43.372Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.372Write1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.372Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.372Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Write1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\a174c1ef10e2077451f5b6dda83242a1a174c1ef10e2077451f5b6dda83242a1
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\AVAST Software
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Avira
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Kaspersky Lab
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\ESET
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Panda Security
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Doctor Web
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\AVG
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\360TotalSecurity
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Bitdefender
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Norton
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Sophos
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\Comodo
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\version.DLL
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\version.dll
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\version.dll
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 0:45:43.387Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 0:45:43.387Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\api-ms-win-downlevel-shlwapi-l2-1-0.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
8/9/2020 - 0:45:43.434Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
8/9/2020 - 0:45:43.434Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\Secur32.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\secur32.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\secur32.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
8/9/2020 - 0:45:43.434Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\api-ms-win-downlevel-advapi32-l2-1-0.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
8/9/2020 - 0:45:43.434Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
8/9/2020 - 0:45:43.434Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
8/9/2020 - 0:45:43.434Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\winhttp.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\winhttp.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\webio.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\webio.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\IPHLPAPI.DLL
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\WINNSI.DLL
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\winnsi.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\winnsi.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\DNSAPI.dll
8/9/2020 - 0:45:43.481Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dnsapi.dll
8/9/2020 - 0:45:43.497Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dnsapi.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\mswsock.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\mswsock.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wship6.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wship6.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
8/9/2020 - 0:45:43.543Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 0:45:43.543Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\netprofm.dll
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\netprofm.dll
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\nlaapi.dll
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\nlaapi.dll
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\dhcpcsvc6.DLL
8/9/2020 - 0:45:43.559Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
8/9/2020 - 0:45:43.622Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
8/9/2020 - 0:45:43.622Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
8/9/2020 - 0:45:43.622Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
8/9/2020 - 0:45:43.622Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
8/9/2020 - 0:45:43.622Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\dhcpcsvc.DLL
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\dhcpcsvc.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\CRYPTSP.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cryptsp.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cryptsp.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rsaenh.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\RpcRtRemote.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\RpcRtRemote.dll
8/9/2020 - 0:45:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\RpcRtRemote.dll
8/9/2020 - 0:45:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\rasadhlp.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rasadhlp.dll
8/9/2020 - 0:45:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\rasadhlp.dll
8/9/2020 - 0:45:43.778Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\npmproxy.dll
8/9/2020 - 0:45:43.778Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\npmproxy.dll
8/9/2020 - 0:45:43.825Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
8/9/2020 - 0:45:43.825Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wininet.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\bdif.exe.Local
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
8/9/2020 - 0:45:43.981Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\WindowsShell.Manifest
8/9/2020 - 0:45:43.981Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\ws2_32.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\ws2_32.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wship6.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wship6.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wship6.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:43.981Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wshqos.dll
8/9/2020 - 0:45:44.840Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wininet.dll
8/9/2020 - 0:45:44.840Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wininet.dll
8/9/2020 - 0:46:29.122Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:46:43.465Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\cmd.exe
8/9/2020 - 0:46:43.465Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\cmd.exe
8/9/2020 - 0:46:43.465Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.465Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.465Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\
8/9/2020 - 0:46:43.653Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:46:43.653Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.653Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\ui\SwDRM.dll
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\ProgramData\1321ba6d1f\REG.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Monitor\REG.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\
8/9/2020 - 0:46:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:46:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Unknown1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.668Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.668Read1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
8/9/2020 - 0:46:43.731Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
8/9/2020 - 0:46:43.731Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:43.731Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:43.731Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.747Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.747Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:43.747Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:43.762Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\ui\SwDRM.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\Prefetch\REG.EXE-4978446A.pf
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\System32\wow64log.dll
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Windows
8/9/2020 - 0:46:43.840Unknown1592C:\Windows\SysWOW64\reg.exeC:\Windows
8/9/2020 - 0:46:43.840Open1592C:\Windows\SysWOW64\reg.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.28Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:46:44.28Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\
8/9/2020 - 0:46:44.43Unknown1528C:\Windows\SysWOW64\cmd.exeC:\
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:44.43Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.43Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.43Read1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.43Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.43Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.43Open1528C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 0:46:44.59Unknown1592C:\Windows\SysWOW64\reg.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:46:44.59Open1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
8/9/2020 - 0:46:44.59Unknown1592C:\Windows\SysWOW64\reg.exeC:\Windows
8/9/2020 - 0:46:44.59Unknown1592C:\Windows\SysWOW64\reg.exeC:\Monitor
8/9/2020 - 0:46:44.59Unknown1592C:\Windows\SysWOW64\reg.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\Prefetch\SCHTASKS.EXE-AD598958.pf
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64win.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64cpu.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\System32\wow64log.dll
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows
8/9/2020 - 0:46:44.59Unknown3032C:\Windows\SysWOW64\schtasks.exeC:\Windows
8/9/2020 - 0:46:44.59Open3032C:\Windows\SysWOW64\schtasks.exeC:\Monitor
8/9/2020 - 0:46:44.75Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.75Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.75Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.75Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\sechost.dll
8/9/2020 - 0:46:44.75Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\ktmw32.dll
8/9/2020 - 0:46:44.75Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\ktmw32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\imm32.dll
8/9/2020 - 0:46:44.90Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.90Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\version.dll
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\version.dll
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\Globalization\Sorting\SortDefault.nls
8/9/2020 - 0:46:44.153Unknown3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Read3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\rpcss.dll
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 0:46:44.153Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\uxtheme.dll
8/9/2020 - 0:46:44.340Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\taskschd.dll
8/9/2020 - 0:46:44.340Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\taskschd.dll
8/9/2020 - 0:46:44.434Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\xmllite.dll
8/9/2020 - 0:46:44.434Open3032C:\Windows\SysWOW64\schtasks.exeC:\Windows\SysWOW64\xmllite.dll
8/9/2020 - 0:46:45.981Unknown3032C:\Windows\SysWOW64\schtasks.exeC:\Windows
8/9/2020 - 0:46:45.981Unknown3032C:\Windows\SysWOW64\schtasks.exeC:\Monitor
8/9/2020 - 0:46:46.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Windows
8/9/2020 - 0:46:46.28Unknown1528C:\Windows\SysWOW64\cmd.exeC:\Monitor
8/9/2020 - 0:47:14.215Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:47:56.340Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\netprofm.dll
8/9/2020 - 0:47:56.340Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\netprofm.dll
8/9/2020 - 0:47:56.340Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\nlaapi.dll
8/9/2020 - 0:47:56.340Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\nlaapi.dll
8/9/2020 - 0:47:56.528Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\npmproxy.dll
8/9/2020 - 0:47:56.528Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\npmproxy.dll
8/9/2020 - 0:47:57.700Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wininet.dll
8/9/2020 - 0:47:57.700Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Windows\SysWOW64\wininet.dll
8/9/2020 - 0:47:59.309Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:48:44.418Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:49:29.622Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\cred.dll
8/9/2020 - 0:49:29.622Open1820C:\ProgramData\1321ba6d1f\bdif.exeC:\Users\Behemot\AppData\Local\Temp\scr.dll

Process
Trace
8/9/2020 - 0:45:43.262Create1480C:\malware.exe1820C:\ProgramData\1321ba6d1f\bdif.exe
8/9/2020 - 0:46:43.653Create1820C:\ProgramData\1321ba6d1f\bdif.exe1528C:\Windows\SysWOW64\cmd.exe
8/9/2020 - 0:46:43.668Create1820C:\ProgramData\1321ba6d1f\bdif.exe1592C:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:44.43Create1528C:\Windows\SysWOW64\cmd.exe3032C:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:44.59Terminate1820C:\ProgramData\1321ba6d1f\bdif.exe1592C:\Windows\SysWOW64\reg.exe
8/9/2020 - 0:46:45.981Terminate1528C:\Windows\SysWOW64\cmd.exe3032C:\Windows\SysWOW64\schtasks.exe
8/9/2020 - 0:46:46.28Terminate1820C:\ProgramData\1321ba6d1f\bdif.exe1528C:\Windows\SysWOW64\cmd.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyEnable
8/9/2020 - 0:45:43.481Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyServer
8/9/2020 - 0:45:43.481Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyOverride
8/9/2020 - 0:45:43.481Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoConfigURL
8/9/2020 - 0:45:43.481Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoDetect
8/9/2020 - 0:45:43.481Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsSavedLegacySettings
8/9/2020 - 0:45:43.543Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ContentCachePrefix
8/9/2020 - 0:45:43.543Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\CookiesCachePrefix
8/9/2020 - 0:45:43.543Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\HistoryCachePrefix
8/9/2020 - 0:45:43.778Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:45:43.778Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:45:43.778Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:45:43.778Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
8/9/2020 - 0:45:45.90Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:45:45.90Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:45:45.90Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:45:45.90Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
8/9/2020 - 0:46:44.59Write1592C:\Windows\SysWOW64\reg.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersStartup
8/9/2020 - 0:47:56.528Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:47:56.528Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:47:56.528Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:47:56.528Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
8/9/2020 - 0:47:57.856Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:47:57.856Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
8/9/2020 - 0:47:57.856Write1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
8/9/2020 - 0:47:57.856Delete1820C:\ProgramData\1321ba6d1f\bdif.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: True check_circle

Deleted
Identified: True check_circle

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: True check_circle

Browsers
Identified: False cancel

Internet
Identified: True check_circle

Loading...

DNS
Query

Response

TCP
Info
computer localhost:65193 arrow_forward help_outline 217.8.117.52:80
computer localhost:65191 arrow_forward help_outline 217.8.117.52:80
computer localhost:65199 arrow_forward help_outline 217.8.117.52:80
computer localhost:65201 arrow_forward help_outline 217.8.117.52:80
computer localhost:65192 arrow_forward help_outline 217.8.117.52:80
computer localhost:65198 arrow_forward help_outline 217.8.117.52:80
computer localhost:65194 arrow_forward help_outline 217.8.117.52:80
computer localhost:65197 arrow_forward help_outline 217.8.117.52:80
computer localhost:65200 arrow_forward help_outline 217.8.117.52:80
computer localhost:65195 arrow_forward help_outline 217.8.117.52:80
computer localhost:65196 arrow_forward help_outline 217.8.117.52:80

UDP
Info
computer localhost:68 arrow_forward help_outline 255.255.255.255:67
computer localhost:67 arrow_forward computer localhost:68

HTTP
Info

Summary
DNS
False cancel

TCP
True check_circle

UDP
True check_circle

HTTP
False cancel

Results
BINARY
NFS 2.0 (Threshold = 0.8)
confidence: 55.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 97.13%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 78.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 49.73%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 90.35%
suspicious: True check_circle

Add to Collection
Download