Report #12968 check_circle

  • Creation Date: Aug. 20, 2021, 12:05 a.m.
  • Last Update: Aug. 20, 2021, 12:36 a.m.
  • File: appidpolicyconverter.exe
  • Results:
Binary
DLL
False cancel
Size
115.00KB
trid
41.0% Win32 Executable MS Visual C++
36.3% Win64 Executable
8.6% Win32 Dynamic Link Library
5.9% Win32 Executable
2.6% OS/2 Executable
type
PE
wordsize
32
Subsystem
Windows CLI
Hashes
md5
211b7bc670814f7406471beab6502211
sha1
b098d0e50539b6ac8cfb844e97cf61316a36d122
crc32
0x751f0a42
sha224
38dbf2cb3a0f25b32963f8272557e8782289a968073cf50aef98d8fd
sha256
9297ea6b9e19078a999f71c06ea9dbe696205bf9cb10df9729e7a5853f27a0f7
sha384
5611cf5db54498a8fbe812c355616d4a1fd1a39fc667de055421d041ffa573e02c86ccedf27d05d2b209fa7920f92a0f
sha512
6ba4b53dade3eaf1fe1e8d0075d0511f0dc64962838a6ce9b210128bb14852d49e6239981f5ff99ae0e4ddfa05ebecff15e10626f44778444cb442a0bf6177cb
ssdeep
3072:EQOwiWGv54F8IlQFOKwPZVCi7TArCgie7:EYiWsD4h6Cgie
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
VC8_Microsoft_Corporation, domain, contentis_base64, IP, win_mutex, Microsoft_Visual_Cpp_8, Visual_Cpp_2005_Release_Microsoft, HasDebugData, IsConsole, maldoc_find_kernel32_base_method_1, IsPE32, HasRichSignature

Suspicious
True check_circle

Imports
ntdll.dll
EtwTraceMessage, NtSetValueKey, NtClose, NtOpenKey, EtwEventWriteTransfer, NtQueryLicenseValue, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwRegisterTraceGuidsW, RtlFreeHeap, RtlAllocateHeap, EtwEventUnregister, EtwEventWrite, RtlNtStatusToDosErrorNoTeb, EtwEventRegister, EtwUnregisterTraceGuids
RPCRT4.dll
UuidFromStringW, RpcStringFreeW, UuidToStringW
msvcrt.dll
_except_handler4_common, _controlfp, ??1type_info@@UAE@XZ, _onexit, __dllonexit, memmove, memcpy, __RTDynamicCast, wcstol, _ui64tow_s, _vsnwprintf_s, _wtoi, towupper, ??0exception@@QAE@ABQBDH@Z, memset, __CxxFrameHandler3, _wsetlocale, _wcsicmp, wcscpy_s, wcsstr, qsort, _wcsnicmp, wcsncmp, swscanf_s, _callnewh, free, malloc, ??0exception@@QAE@XZ, ??0exception@@QAE@ABV0@@Z, _purecall, ??1exception@@UAE@XZ, ?what@exception@@UBEPBDXZ, _CxxThrowException, _XcptFilter, __p__commode, _amsg_exit, __wgetmainargs, __set_app_type, exit, _exit, _cexit, __p__fmode, __setusermatherr, _initterm, ?terminate@@YAXXZ, _lock, _unlock
srpapi.dll
AppIDFreeAttributeString, AppIDEncodeAttributeString
USERENV.dll
LeaveCriticalPolicySection, EnterCriticalPolicySection
msvcp110_win.dll
?_Syserror_map@std@@YAPBDH@Z, ?_Xlength_error@std@@YAXPBD@Z, ?_Winerror_map@std@@YAPBDH@Z, ?_Xout_of_range@std@@YAXPBD@Z, ?_Xbad_alloc@std@@YAXXZ
api-ms-win-core-io-l1-1-0.dll
DeviceIoControl
api-ms-win-core-com-l1-1-0.dll
CoInitializeSecurity, CoCreateInstance, CoUninitialize
api-ms-win-core-file-l1-1-0.dll
FindNextFileW, DeleteFileW, FindClose, FlushFileBuffers, WriteFile, CreateFileW, FindFirstFileW
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-heap-l1-1-0.dll
HeapSetInformation
api-ms-win-core-heap-l2-1-0.dll
LocalFree
api-ms-win-core-synch-l1-1-0.dll
SleepEx, CreateMutexExW, WaitForSingleObject, ReleaseMutex
api-ms-win-core-synch-l1-2-0.dll
Sleep
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-sysinfo-l1-1-0.dll
GetWindowsDirectoryW, GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-registry-l1-1-0.dll
RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteTreeW, RegSetValueExW, RegGetValueW, RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW
api-ms-win-security-base-l1-1-0.dll
GetAce, GetSecurityDescriptorDacl
api-ms-win-core-delayload-l1-1-0.dll
DelayLoadFailureHook
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI
api-ms-win-core-namespace-l1-1-0.dll
CreateBoundaryDescriptorW, DeleteBoundaryDescriptor, AddSIDToBoundaryDescriptor, CreatePrivateNamespaceW, ClosePrivateNamespace, OpenPrivateNamespaceW
api-ms-win-appmodel-runtime-l1-1-0.dll
PackageNameAndPublisherIdFromFamilyName, PackageFamilyNameFromId
api-ms-win-eventing-provider-l1-1-0.dll
EventRegister, EventUnregister, EventSetInformation, EventWriteTransfer, EventActivityIdControl
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, GetLastError, SetUnhandledExceptionFilter
api-ms-win-core-libraryloader-l1-2-0.dll
GetModuleHandleW
api-ms-win-service-management-l1-1-0.dll
OpenSCManagerW, CloseServiceHandle, OpenServiceW
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, ChangeServiceConfigW
api-ms-win-core-processthreads-l1-1-0.dll
TerminateProcess, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId
Strings
List
appidpolicyconverter.pdb
\REGISTRY\MACHINE\System\CurrentControlSet\Control\AppID\Configuration\SMARTLOCKER
APPID://SHA256HASH
APPID://SHA1HASH
Microsoft.Windows.Security.AppIdLogger
APPID://SHA256FLATHASH
name="Microsoft.Windows.Security.AppIDPolicyConverter"
api-ms-win-security-sddl-l1-1-0.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-security-base-l1-1-0.dll
USERENV.dll
ntdll.dll
srpapi.dll
Software\Policies\Microsoft\Windows\AppidPlugins
System\CurrentControlSet\Control\AppID\Configuration\SMARTLOCKER
\\.\SrpDevice
\System32\AppLocker\
\System32\AppLocker\*.Applocker
\System32\AppLocker\MDM\*
api-ms-win-core-processthreads-l1-1-0.dll
APPID://PATH
api-ms-win-core-sysinfo-l1-1-0.dll
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-errorhandling-l1-1-0.dll
ruleCount
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-delayload-l1-1-0.dll
api-ms-win-core-delayload-l1-1-1.dll
api-ms-win-service-management-l1-1-0.dll
api-ms-win-service-management-l2-1-0.dll
api-ms-win-core-namespace-l1-1-0.dll
api-ms-win-core-file-l2-1-0.dll
api-ms-win-core-file-l1-1-0.dll
api-ms-win-core-io-l1-1-0.dll
api-ms-win-core-synch-l1-1-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-core-heap-l1-1-0.dll
api-ms-win-core-com-l1-1-0.dll
Software\Policies\Microsoft\Windows\SrpV2
api-ms-win-eventing-provider-l1-1-0.dll
api-ms-win-appmodel-runtime-l1-1-0.dll
APPID://FQBN
api-ms-win-core-handle-l1-1-0.dll
System\CurrentControlSet\Control\AppID\Configuration
AppIDPolicyConverter.exe
AppIDPolicyConverter.exe
appidpolicyconverter.exe
System\CurrentControlSet\Control\Srp\GP\
msvcp110_win.dll
.AppLocker
_wcsnicmp
_wcsicmp
Plugin.Config
<requestedPrivileges>
SShp!@
PluginPolicyData
pluginFlags
TerminateProcess
pluginName
pluginId
DeviceIoControl
CoCreateInstance
MANAGEDINSTALLER
RegGetValueW
DeleteFileW
WriteFile
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
CreateFileW
RegCreateKeyExW
OpenSCManagerW
MoveFileExW
OpenServiceW
FindFirstFileW
FindNextFileW
RegEnumKeyExW
GetModuleHandleW
QueryPerformanceCounter
Microsoft Corporation. All rights reserved.
GetTickCount
SHA256Flat
SleepEx
6 6@6H6T6t6|6
Sleep
FileHashCondition
FileHash
FileHashRule
system
<requestedExecutionLevel
Applocker Private\LowBox ACE
Applocker Private\LPAC ACE
10.0.19041.906 (WinBuild.160101.0800)
909E9a9h9o9}9
3 3%323A3I3Q3e3m3u3{3
ApplockerPolicyData
293G3^3e3n3s3
version="5.1.0.0"
5s5A6F708[8~8

Foremost
Matches
0.exe, 115 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Files
Allowed: ntdll.dll, api-ms-win-core-synch-l1-2-0.dll, USERENV.dll, api-ms-win-core-file-l1-1-0.dll, api-ms-win-core-synch-l1-1-0.dll, api-ms-win-core-handle-l1-1-0.dll, ole32.dll, api-ms-win-core-processthreads-l1-1-0.dll, api-ms-win-core-heap-l1-1-0.dll, api-ms-win-core-profile-l1-1-0.dll, api-ms-win-security-base-l1-1-0.dll, api-ms-win-core-delayload-l1-1-1.dll, api-ms-win-appmodel-runtime-l1-1-0.dll, RPCRT4.dll, srpapi.dll, api-ms-win-service-management-l2-1-0.dll, api-ms-win-core-delayload-l1-1-0.dll, msvcrt.dll, api-ms-win-core-libraryloader-l1-2-0.dll, msvcp110_win.dll, api-ms-win-core-com-l1-1-0.dll, api-ms-win-core-namespace-l1-1-0.dll, api-ms-win-core-file-l2-1-0.dll, OLEAUT32.dll, api-ms-win-core-io-l1-1-0.dll, api-ms-win-service-management-l1-1-0.dll, api-ms-win-eventing-provider-l1-1-0.dll, api-ms-win-security-sddl-l1-1-0.dll, api-ms-win-core-registry-l1-1-0.dll, api-ms-win-core-heap-l2-1-0.dll, api-ms-win-core-errorhandling-l1-1-0.dll, api-ms-win-core-sysinfo-l1-1-0.dll
hasFiles: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 18432
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 8192
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 175430
Suspicous: False cancel

Sections
Allowed: .text, .data, .idata, .didat, .rsrc, .reloc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 10
Suspicious: False cancel
Image
Version: False cancel
Suspicious: 10
Linker
Version: 14.20
Suspicious: False cancel
Subsystem
Version: 10.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 79008
Suspicious: False cancel

Anomalies
Anomalies
hasAnomalies: False cancel

Libraries
Allowed: ntdll.dll, api-ms-win-core-synch-l1-2-0.dll, userenv.dll, api-ms-win-core-file-l1-1-0.dll, api-ms-win-core-synch-l1-1-0.dll, api-ms-win-core-handle-l1-1-0.dll, ole32.dll, api-ms-win-core-processthreads-l1-1-0.dll, api-ms-win-core-heap-l1-1-0.dll, api-ms-win-core-profile-l1-1-0.dll, api-ms-win-security-base-l1-1-0.dll, api-ms-win-core-delayload-l1-1-1.dll, api-ms-win-appmodel-runtime-l1-1-0.dll, rpcrt4.dll, api-ms-win-service-management-l2-1-0.dll, api-ms-win-core-delayload-l1-1-0.dll, msvcrt.dll, api-ms-win-core-com-l1-1-0.dll, api-ms-win-core-namespace-l1-1-0.dll, api-ms-win-core-file-l2-1-0.dll, oleaut32.dll, api-ms-win-core-io-l1-1-0.dll, api-ms-win-service-management-l1-1-0.dll, api-ms-win-eventing-provider-l1-1-0.dll, api-ms-win-security-sddl-l1-1-0.dll, api-ms-win-core-registry-l1-1-0.dll, api-ms-win-core-errorhandling-l1-1-0.dll, api-ms-win-core-sysinfo-l1-1-0.dll
hasLibs: True check_circle
Suspicious: srpapi.dll, api-ms-win-core-libraryloader-l1-2-0.dll, msvcp110_win.dll, api-ms-win-core-heap-l2-1-0.dll
hasAllowed: True check_circle
hasSuspicious: True check_circle

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2099-07-20 05:00:10
Future: True check_circle

Compilation
Packed: False cancel
Missing: False cancel
Packers
Compiled: True check_circle
Compilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
ldr
.text: 2

pushret
.text: 4
.idata: 2

pushpopmath
.reloc: 4

sizeofimage
.text: 2

ss register
.reloc: 1

garbagebytes
.text: 4
.idata: 2

hookdetection
.reloc: 2

stealthimport
.idata: 1

isdebbugerpresent
.text: 1

software breakpoint
.text: 1
.reloc: 1

programcontrolflowchange
.text: 4
.idata: 2

AVclass
None
1
VirusTotal
md5
211b7bc670814f7406471beab6502211
sha1
b098d0e50539b6ac8cfb844e97cf61316a36d122
SCANS (DETECTION RATE = 0.00%)
CMC
update: 20210504
version: 2.10.2019.1
detected: False cancel

MAX
update: 20210505
version: 2019.9.16.1
detected: False cancel

APEX
update: 20210504
version: 6.160
detected: False cancel

Bkav
update: 20210504
version: 1.3.0.9899
detected: False cancel

K7GW
update: 20210504
version: 11.180.37081
detected: False cancel

ALYac
update: 20210505
version: 1.1.3.1
detected: False cancel

Avast
update: 20210505
version: 21.1.5827.0
detected: False cancel

Avira
update: 20210505
version: 8.3.3.12
detected: False cancel

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cynet
update: 20210505
version: 4.0.0.27
detected: False cancel

Cyren
update: 20210505
version: 6.3.0.2
detected: False cancel

DrWeb
update: 20210505
version: 7.0.49.9080
detected: False cancel

GData
update: 20210505
version: A:25.29527B:27.22892
detected: False cancel

Panda
update: 20210504
version: 4.6.4.2
detected: False cancel

VBA32
update: 20210504
version: 5.0.0
detected: False cancel

VIPRE
update: 20210504
version: 92316
detected: False cancel

Zoner
update: 20210504
version: 0.0.0.0
detected: False cancel

ClamAV
update: 20210504
version: 0.103.2.0
detected: False cancel

Comodo
update: 20210504
version: 33498
detected: False cancel

Ikarus
update: 20210504
version: 0.1.5.2
detected: False cancel

Lionic
update: 20210505
version: 4.2
detected: False cancel

McAfee
update: 20210504
version: 6.0.6.653
detected: False cancel

Rising
update: 20210504
version: 25.0.0.26
detected: False cancel

Sophos
update: 20210504
version: 1.0.2.0
detected: False cancel

Yandex
update: 20210502
version: 5.5.2.24
detected: False cancel

Zillya
update: 20210503
version: 2.0.0.4355
detected: False cancel

Acronis
update: 20210211
version: 1.1.1.81
detected: False cancel

Alibaba
update: 20190527
version: 0.3.0.5
detected: False cancel

Arcabit
update: 20210504
version: 1.0.0.886
detected: False cancel

Cylance
update: 20210505
version: 2.3.1.101
detected: False cancel

Elastic
update: 20210420
version: 4.0.21
detected: False cancel

FireEye
update: 20210505
version: 32.44.1.0
detected: False cancel

Sangfor
update: 20210416
version: 2.9.0.0
detected: False cancel

TACHYON
update: 20210505
version: 2021-05-05.01
detected: False cancel

Tencent
update: 20210505
version: 1.0.0.1
detected: False cancel

ViRobot
update: 20210504
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20210505
version: 1.0.0.403
detected: False cancel

Ad-Aware
update: 20210505
version: 3.0.21.179
detected: False cancel

Emsisoft
update: 20210505
version: 2018.12.0.1641
detected: False cancel

F-Secure
update: 20210331
version: 12.0.86.52
detected: False cancel

Fortinet
update: 20210505
version: 6.2.142.0
detected: False cancel

Jiangmin
update: 20210504
version: 16.0.100
detected: False cancel

Kingsoft
update: 20210505
version: 2017.9.26.565
detected: False cancel

Paloalto
update: 20210505
version: 1.0
detected: False cancel

Symantec
update: 20210504
version: 1.14.0.0
detected: False cancel

AhnLab-V3
update: 20210505
version: 3.20.0.10177
detected: False cancel

Antiy-AVL
update: 20210504
version: 3.0.0.1
detected: False cancel

Kaspersky
update: 20210504
version: 21.0.1.45
detected: False cancel

MaxSecure
update: 20210503
version: 1.0.0.1
detected: False cancel

Microsoft
update: 20210505
version: 1.1.18100.5
detected: False cancel

Qihoo-360
update: 20210505
version: 1.0.0.1120
detected: False cancel

ZoneAlarm
update: 20210504
version: 1.0
detected: False cancel

Cybereason
update: 20210330
version: 1.2.449
detected: False cancel

ESET-NOD32
update: 20210505
version: 23242
detected: False cancel

Gridinsoft
update: 20210505
version: 1.0.39.131
detected: False cancel

TrendMicro
update: 20210505
version: 11.0.0.1006
detected: False cancel

BitDefender
update: 20210505
version: 7.2
detected: False cancel

CrowdStrike
update: 20210203
version: 1.0
detected: False cancel

K7AntiVirus
update: 20210504
version: 11.180.37081
detected: False cancel

SentinelOne
update: 20210215
version: 5.0.0.20
detected: False cancel

Malwarebytes
update: 20210504
version: 4.2.2.27
detected: False cancel

CAT-QuickHeal
update: 20210504
version: 14.00
detected: False cancel

NANO-Antivirus
update: 20210505
version: 1.0.146.25279
detected: False cancel

BitDefenderTheta
update: 20210504
version: 7.2.37796.0
detected: False cancel

MicroWorld-eScan
update: 20210504
version: 14.0.409.0
detected: False cancel

SUPERAntiSpyware
update: 20210430
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
update: 20210504
version: v2019.1.2+3728
detected: False cancel

TrendMicro-HouseCall
update: 20210504
version: 10.0.0.1040
detected: False cancel

total
68
sha256
9297ea6b9e19078a999f71c06ea9dbe696205bf9cb10df9729e7a5853f27a0f7
scan_id
9297ea6b9e19078a999f71c06ea9dbe696205bf9cb10df9729e7a5853f27a0f7-1620184190
resource
211b7bc670814f7406471beab6502211
positives
0
scan_date
2021-05-05 03:09:50
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
19/8/2021 - 23:45:44.481Unknown4C:\Users\Behemot\Desktop\desktop.ini
19/8/2021 - 23:45:44.481Unknown4C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:46.465Write4C:\Users\Behemot
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A2F27954F4B4C5FD26
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A2F27954F4B4C5FD26TMP000000A2F27954F4B4C5FD26
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Read2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Read2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Read2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Read2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A30415A103D3F52066
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A30415A103D3F52066TMP000000A30415A103D3F52066
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe:Zone.Identifier
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe:Zone.Identifier
19/8/2021 - 23:45:48.856Read2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe:Zone.Identifier
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A30415A103D3F52066TMP000000A30415A103D3F52066
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Open2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exe
19/8/2021 - 23:45:48.856Unknown2928C:\Windows\System32\svchost.exeC:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:48.872Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:48.918Unknown2928C:\Windows\System32\svchost.exeC:\Windows\Temp\TMP000000A2F27954F4B4C5FD26TMP000000A2F27954F4B4C5FD26
19/8/2021 - 23:45:50.465Unknown4C:\Monitor\WKCD_Load_Use.exeWKCD_Load_Use.exe
19/8/2021 - 23:45:50.465Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:50.465Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:53.856Open2928C:\Windows\System32\svchost.exeC:\Windows\System32\conhost.exe
19/8/2021 - 23:45:53.856Open2928C:\Windows\System32\svchost.exeC:\Windows\System32\conhost.exe
19/8/2021 - 23:45:53.856Open2928C:\Windows\System32\svchost.exeC:\Windows\System32\conhost.exe
19/8/2021 - 23:45:53.856Open2928C:\Windows\System32\svchost.exeC:\Windows\System32\conhost.exe
19/8/2021 - 23:45:54.75Open796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.75Open796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.75Write796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pfWKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.75Unknown796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pfWKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.90Open796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.90Unknown796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.90Open796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.90Write796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.90Unknown796C:\Windows\System32\svchost.exeC:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.497Write4C:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pfWKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.497Write4C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.497Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:54.497Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:54.497Unknown4C:\Windows\Prefetch\WKCD_LOAD_USE.EXE-695C7827.pfWKCD_LOAD_USE.EXE-695C7827.pf
19/8/2021 - 23:45:54.497Unknown4C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:54.497Unknown4C:\Windows\Prefetch\CONHOST.EXE-1F3E9D7E.pfCONHOST.EXE-1F3E9D7E.pf
19/8/2021 - 23:45:56.465Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:56.465Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:45:56.762Write4C:\Monitor
19/8/2021 - 23:45:59.512Write684C:\Windows\System32\svchost.exeC:\Windows\System32\winevt\Logs\System.evtx
19/8/2021 - 23:45:59.512Write684C:\Windows\System32\svchost.exeC:\Windows\System32\winevt\Logs\System.evtx
19/8/2021 - 23:45:59.512Write684C:\Windows\System32\svchost.exeC:\Windows\System32\winevt\Logs\Security.evtx
19/8/2021 - 23:45:59.512Write684C:\Windows\System32\svchost.exeC:\Windows\System32\winevt\Logs\Security.evtx
19/8/2021 - 23:46:0.497Write4C:\Windows\System32\winevt\Logs\System.evtx
19/8/2021 - 23:46:0.497Write4C:\Windows\System32\winevt\Logs\Security.evtx
19/8/2021 - 23:46:2.497Write4C:\Windows\System32\winevt\Logs\System.evtx
19/8/2021 - 23:46:2.497Write4C:\Windows\System32\winevt\Logs\Security.evtx
19/8/2021 - 23:46:2.497Unknown4C:\Windows\System32\winevt\Logs\System.evtx
19/8/2021 - 23:46:2.497Unknown4C:\Windows\System32\winevt\Logs\Security.evtx
19/8/2021 - 23:46:10.481Write4C:\Windows\Temp
19/8/2021 - 23:46:10.481Write4C:\Windows
19/8/2021 - 23:46:17.497Write684C:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve.LOG1
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.418Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.434Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.434Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.434Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.434Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:27.434Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:46:27.528Write4C:\System Volume Information\Syscache.hve
19/8/2021 - 23:46:30.450Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:46:30.450Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM.LOG1
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM.LOG1
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM.LOG1
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM.LOG1
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM
19/8/2021 - 23:46:37.528Write4C:\Windows\System32\config\SYSTEM
19/8/2021 - 23:46:55.997Open528C:\Windows\System32\SearchIndexer.exeC:\ProgramData\Microsoft\Search\Data
19/8/2021 - 23:46:55.997Unknown528C:\Windows\System32\SearchIndexer.exeC:\ProgramData\Microsoft\Search\Data
19/8/2021 - 23:47:17.465Write684C:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
19/8/2021 - 23:47:27.559Open1864C:\Windows\explorer.exeC:\
19/8/2021 - 23:47:27.559Unknown1864C:\Windows\explorer.exeC:\
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot
19/8/2021 - 23:47:32.809Unknown1864C:\Windows\explorer.exeC:\Users\Behemot
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot\AppData\Roaming
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot\AppData\Roaming
19/8/2021 - 23:47:32.809Unknown1864C:\Windows\explorer.exeC:\Users\Behemot\AppData\Roaming
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Themes
19/8/2021 - 23:47:32.809Open1864C:\Windows\explorer.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Themes\slideshow.ini
19/8/2021 - 23:47:35.856Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Open796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:47:35.856Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Unknown796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:47:35.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:47:35.856Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:47:35.856Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:47:38.872Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:47:38.872Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:47:40.606Read1232C:\Program Files\Windows Media Player\wmpnetwk.exeC:\Program Files\Windows Media Player\wmpnetwk.exe
19/8/2021 - 23:48:11.309Open4\Device\HarddiskVolume1\System Volume Information
19/8/2021 - 23:48:11.309Unknown4\Device\HarddiskVolume1\System Volume Information
19/8/2021 - 23:48:13.59Open4C:\System Volume Information
19/8/2021 - 23:48:13.59Open4C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
19/8/2021 - 23:48:13.59Open4C:\System Volume Information\{bcf7d7ec-4f18-11e8-8b8a-525400842a13}{3808876b-c176-4e48-b7ae-04046e6cc752}
19/8/2021 - 23:48:13.59Open4C:\System Volume Information\{bcf7d7f0-4f18-11e8-8b8a-525400842a13}{3808876b-c176-4e48-b7ae-04046e6cc752}
19/8/2021 - 23:48:13.59Unknown4C:\System Volume Information
19/8/2021 - 23:48:25.887Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Open796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:48:25.887Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:48:25.887Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:48:28.903Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:48:28.903Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:48:32.465Write684C:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Feeds Cache\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Feeds Cache\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IECompatCache\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IECompatCache\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IECompatUACache\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IECompatUACache\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\DNTException\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\DNTException\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\EmieSiteList\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\EmieUserList\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\EmieUserList\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\DOMStore\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Internet Explorer\DOMStore\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018050320180504\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018050320180504\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\AppCache\B2419NGQ\container.dat
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\AppCache\B2419NGQ\container.datcontainer.dat
19/8/2021 - 23:49:20.684Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:20.684Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:20.684Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:20.731Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.731Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.825Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.825Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.918Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.918Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.918Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.918Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.918Read1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:20.965Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.965Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.965Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.965Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.log
19/8/2021 - 23:49:20.965Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:21.12Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:21.12Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:21.59Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat
19/8/2021 - 23:49:21.59Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.datcontainer.dat
19/8/2021 - 23:49:21.59Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:21.59Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:21.59Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.dat
19/8/2021 - 23:49:21.59Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\container.datcontainer.dat
19/8/2021 - 23:49:23.684Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:23.684Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:25.887Unknown2360C:\Windows\System32\audiodg.exeC:\Windows
19/8/2021 - 23:49:30.731Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:30.731Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:30.778Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:30.778Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users\Behemot
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Open1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Unknown1796C:\Windows\System32\taskhost.exeC:\Users
19/8/2021 - 23:49:30.825Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:30.825Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:30.825Write1796C:\Windows\System32\taskhost.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Write4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:30.825Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:30.825Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:30.856Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:30.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:30.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:30.856Open796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:49:30.856Open796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:30.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:30.856Unknown796C:\Windows\System32\svchost.exe\Device\Mup\.\.\
19/8/2021 - 23:49:30.856Unknown796C:\Windows\System32\svchost.exeC:\Windows\CSC\v2.0.6\namespace
19/8/2021 - 23:49:31.481Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:31.481Unknown4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:31.481Unknown4C:\Users\Behemot\AppData\Local\Microsoft\Windows\WebCache\V01.chk
19/8/2021 - 23:49:31.481Write2948C:\Monitor\WKCD_Load_Use.exeC:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:31.481Unknown4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:32.465Write684C:\Windows\System32\svchost.exeC:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
19/8/2021 - 23:49:33.497Write4C:\Monitor\Files\Logs\File.log
19/8/2021 - 23:49:33.497Unknown4C:\Monitor\Files\Logs\File.log

Process
Trace
19/8/2021 - 23:49:25.887Terminate684C:\Windows\System32\svchost.exe2360C:\Windows\System32\audiodg.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruListCurrentLru
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000EDObjectId
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000EDObjectLru
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\ObjectTable\1E_ObjectLru_
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000E8ObjectId
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000E8ObjectLru
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\ObjectTable\3E_ObjectLru_
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000EBObjectId
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000EBObjectLru
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\ObjectTable\3F_ObjectLru_
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000F0ObjectId
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\LruList\00000000000000F0ObjectLru
19/8/2021 - 23:46:22.418Write4\REGISTRY\A\{BCF7D7EA-4F18-11E8-8B8A-525400842A13}\DefaultObjectStore\ObjectTable\40_ObjectLru_
19/8/2021 - 23:46:29.278Write4\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\22
19/8/2021 - 23:46:29.278Write4\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24ffffffffffffffffffffffffffffff00
19/8/2021 - 23:46:29.278Write4\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24ffffffffffffffffffffffffffffff01
19/8/2021 - 23:46:29.278Write4\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24ffffffffffffffffffffffffffffff02
19/8/2021 - 23:46:29.278Write4\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\24ffffffffffffffffffffffffffffff03

File Summary
Created
Identified: True check_circle

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: True check_circle

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

Loading...

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
NFS 2.0 (Threshold = 0.8)
confidence: 85.00%
suspicious: False cancel

NFS 3.0 (Threshold = 0.75)
confidence: 76.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 99.82%
suspicious: False cancel

Random Forest (100 estimators, NFS-BRMalware)
confidence: 86.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 42.03%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 100.00%
suspicious: False cancel

Add to Collection
Download