File name:

lol.bat

Full analysis: https://app.any.run/tasks/ac1f2240-7a75-448d-9819-400c3a5548fe
Verdict: Malicious activity
Analysis date: November 02, 2023, 16:12:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text
MD5:

E01EFE13199C3789E451111ED9BCBAD5

SHA1:

0CFDCD17F51E360A902A19ABE962AD165591C313

SHA256:

267F5C765EC5C17B4671D8B2585A7D8A90F5A00337411405D7856251280E9E17

SSDEEP:

3:jlEaGukn2bGuk9RFmGukJ:ZEaGuG4GuPGuC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 3156)
      • cmd.exe (PID: 3220)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 3576)
      • cmd.exe (PID: 3596)
      • cmd.exe (PID: 3524)
      • cmd.exe (PID: 3464)
      • cmd.exe (PID: 3852)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 3812)
      • cmd.exe (PID: 3928)
      • cmd.exe (PID: 3632)
      • cmd.exe (PID: 3660)
      • cmd.exe (PID: 3908)
      • cmd.exe (PID: 4064)
      • cmd.exe (PID: 4020)
      • cmd.exe (PID: 3752)
      • cmd.exe (PID: 3972)
      • cmd.exe (PID: 3748)
      • cmd.exe (PID: 4088)
      • cmd.exe (PID: 4068)
      • cmd.exe (PID: 3696)
      • cmd.exe (PID: 4060)
      • cmd.exe (PID: 4048)
      • cmd.exe (PID: 3672)
      • cmd.exe (PID: 3820)
      • cmd.exe (PID: 2060)
      • cmd.exe (PID: 1628)
      • cmd.exe (PID: 1808)
      • cmd.exe (PID: 608)
      • cmd.exe (PID: 316)
      • cmd.exe (PID: 1152)
      • cmd.exe (PID: 1360)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 2164)
      • cmd.exe (PID: 1904)
      • cmd.exe (PID: 1812)
      • cmd.exe (PID: 1272)
      • cmd.exe (PID: 1236)
      • cmd.exe (PID: 2392)
      • cmd.exe (PID: 1644)
      • cmd.exe (PID: 2632)
      • cmd.exe (PID: 1036)
      • cmd.exe (PID: 2300)
      • cmd.exe (PID: 2328)
      • cmd.exe (PID: 3800)
      • cmd.exe (PID: 2560)
      • cmd.exe (PID: 2724)
      • cmd.exe (PID: 1088)
      • cmd.exe (PID: 3796)
      • cmd.exe (PID: 1584)
      • cmd.exe (PID: 2400)
      • cmd.exe (PID: 2120)
      • cmd.exe (PID: 2176)
      • cmd.exe (PID: 2836)
      • cmd.exe (PID: 1700)
      • cmd.exe (PID: 280)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 3044)
      • cmd.exe (PID: 2692)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 2232)
      • cmd.exe (PID: 880)
      • cmd.exe (PID: 2908)
      • cmd.exe (PID: 888)
      • cmd.exe (PID: 372)
      • cmd.exe (PID: 3048)
      • cmd.exe (PID: 3012)
      • cmd.exe (PID: 2436)
      • cmd.exe (PID: 3316)
      • cmd.exe (PID: 3052)
      • cmd.exe (PID: 3056)
      • cmd.exe (PID: 3128)
      • cmd.exe (PID: 2976)
      • cmd.exe (PID: 3216)
      • cmd.exe (PID: 3420)
      • cmd.exe (PID: 3876)
      • cmd.exe (PID: 1436)
      • cmd.exe (PID: 3592)
      • cmd.exe (PID: 3724)
      • cmd.exe (PID: 3816)
      • cmd.exe (PID: 1880)
      • cmd.exe (PID: 1696)
      • cmd.exe (PID: 3868)
      • cmd.exe (PID: 2684)
      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 2516)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 2116)
      • cmd.exe (PID: 2860)
      • cmd.exe (PID: 4100)
      • cmd.exe (PID: 4124)
      • cmd.exe (PID: 4148)
      • cmd.exe (PID: 4244)
      • cmd.exe (PID: 4196)
      • cmd.exe (PID: 4220)
      • cmd.exe (PID: 4292)
      • cmd.exe (PID: 4268)
      • cmd.exe (PID: 4172)
      • cmd.exe (PID: 4340)
      • cmd.exe (PID: 4364)
      • cmd.exe (PID: 4412)
      • cmd.exe (PID: 4388)
      • cmd.exe (PID: 4316)
      • cmd.exe (PID: 4460)
      • cmd.exe (PID: 4484)
      • cmd.exe (PID: 4508)
      • cmd.exe (PID: 4532)
      • cmd.exe (PID: 4436)
      • cmd.exe (PID: 4612)
      • cmd.exe (PID: 4636)
      • cmd.exe (PID: 4684)
      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 4556)
      • cmd.exe (PID: 4588)
      • cmd.exe (PID: 4756)
      • cmd.exe (PID: 4780)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 4708)
      • cmd.exe (PID: 4732)
      • cmd.exe (PID: 4852)
      • cmd.exe (PID: 4900)
      • cmd.exe (PID: 4924)
      • cmd.exe (PID: 4948)
      • cmd.exe (PID: 4828)
      • cmd.exe (PID: 4876)
      • cmd.exe (PID: 4996)
      • cmd.exe (PID: 5020)
      • cmd.exe (PID: 5044)
      • cmd.exe (PID: 4972)
      • cmd.exe (PID: 5068)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 5116)
      • cmd.exe (PID: 5140)
      • cmd.exe (PID: 5164)
      • cmd.exe (PID: 5188)
      • cmd.exe (PID: 5212)
      • cmd.exe (PID: 5236)
      • cmd.exe (PID: 5260)
      • cmd.exe (PID: 5284)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5332)
      • cmd.exe (PID: 5452)
      • cmd.exe (PID: 5356)
      • cmd.exe (PID: 5380)
      • cmd.exe (PID: 5404)
      • cmd.exe (PID: 5428)
      • cmd.exe (PID: 5500)
      • cmd.exe (PID: 5524)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5572)
      • cmd.exe (PID: 5596)
      • cmd.exe (PID: 5476)
      • cmd.exe (PID: 5644)
      • cmd.exe (PID: 5692)
      • cmd.exe (PID: 5668)
      • cmd.exe (PID: 5716)
      • cmd.exe (PID: 5620)
      • cmd.exe (PID: 5764)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 5812)
      • cmd.exe (PID: 5740)
      • cmd.exe (PID: 5932)
      • cmd.exe (PID: 5908)
      • cmd.exe (PID: 5884)
      • cmd.exe (PID: 5860)
      • cmd.exe (PID: 5836)
      • cmd.exe (PID: 5956)
      • cmd.exe (PID: 6028)
      • cmd.exe (PID: 6052)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 6100)
      • cmd.exe (PID: 5980)
      • cmd.exe (PID: 6004)
      • cmd.exe (PID: 4136)
      • cmd.exe (PID: 4424)
      • cmd.exe (PID: 3684)
      • cmd.exe (PID: 6124)
      • cmd.exe (PID: 4280)
      • cmd.exe (PID: 4672)
      • cmd.exe (PID: 4816)
      • cmd.exe (PID: 4960)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 5224)
      • cmd.exe (PID: 4584)
      • cmd.exe (PID: 2808)
      • cmd.exe (PID: 6064)
      • cmd.exe (PID: 5632)
      • cmd.exe (PID: 5776)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 5368)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 4496)
      • cmd.exe (PID: 5152)
      • cmd.exe (PID: 6156)
      • cmd.exe (PID: 6180)
      • cmd.exe (PID: 6204)
      • cmd.exe (PID: 6256)
      • cmd.exe (PID: 6232)
      • cmd.exe (PID: 6280)
      • cmd.exe (PID: 6304)
      • cmd.exe (PID: 6328)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6376)
      • cmd.exe (PID: 6400)
      • cmd.exe (PID: 6476)
      • cmd.exe (PID: 6548)
      • cmd.exe (PID: 6500)
      • cmd.exe (PID: 6524)
      • cmd.exe (PID: 6428)
      • cmd.exe (PID: 6452)
      • cmd.exe (PID: 6596)
      • cmd.exe (PID: 6620)
      • cmd.exe (PID: 6644)
      • cmd.exe (PID: 6668)
      • cmd.exe (PID: 6572)
      • cmd.exe (PID: 6740)
      • cmd.exe (PID: 6764)
      • cmd.exe (PID: 6788)
      • cmd.exe (PID: 6812)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 6716)
      • cmd.exe (PID: 6864)
      • cmd.exe (PID: 6888)
      • cmd.exe (PID: 6912)
      • cmd.exe (PID: 6936)
      • cmd.exe (PID: 6960)
      • cmd.exe (PID: 6840)
      • cmd.exe (PID: 7008)
      • cmd.exe (PID: 7032)
      • cmd.exe (PID: 6984)
      • cmd.exe (PID: 7056)
      • cmd.exe (PID: 7080)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 7176)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7128)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 7280)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7352)
      • cmd.exe (PID: 7252)
      • cmd.exe (PID: 7328)
      • cmd.exe (PID: 7424)
      • cmd.exe (PID: 7496)
      • cmd.exe (PID: 7472)
      • cmd.exe (PID: 7376)
      • cmd.exe (PID: 7400)
      • cmd.exe (PID: 7448)
      • cmd.exe (PID: 7572)
      • cmd.exe (PID: 7620)
      • cmd.exe (PID: 7520)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7668)
      • cmd.exe (PID: 7716)
      • cmd.exe (PID: 7740)
      • cmd.exe (PID: 7764)
      • cmd.exe (PID: 7644)
      • cmd.exe (PID: 7692)
      • cmd.exe (PID: 7812)
      • cmd.exe (PID: 7840)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 7888)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 8036)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 6216)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 8084)
      • cmd.exe (PID: 8156)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 6656)
      • cmd.exe (PID: 6948)
      • cmd.exe (PID: 6800)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 7092)
      • cmd.exe (PID: 7364)
      • cmd.exe (PID: 7532)
      • cmd.exe (PID: 7680)
      • cmd.exe (PID: 7240)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 6584)
      • cmd.exe (PID: 7020)
      • cmd.exe (PID: 7824)
      • cmd.exe (PID: 7976)
      • cmd.exe (PID: 7436)
      • cmd.exe (PID: 8208)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8284)
      • cmd.exe (PID: 8308)
      • cmd.exe (PID: 8332)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8476)
      • cmd.exe (PID: 8500)
      • cmd.exe (PID: 8528)
      • cmd.exe (PID: 8404)
      • cmd.exe (PID: 8428)
      • cmd.exe (PID: 8452)
      • cmd.exe (PID: 8576)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 8648)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 8600)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 8768)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 8696)
      • cmd.exe (PID: 8916)
      • cmd.exe (PID: 8868)
      • cmd.exe (PID: 8892)
      • cmd.exe (PID: 8796)
      • cmd.exe (PID: 8820)
      • cmd.exe (PID: 8844)
      • cmd.exe (PID: 9036)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 9012)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 8940)
      • cmd.exe (PID: 8964)
      • cmd.exe (PID: 9136)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9184)
      • cmd.exe (PID: 9084)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 9256)
      • cmd.exe (PID: 9232)
      • cmd.exe (PID: 9280)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 9356)
      • cmd.exe (PID: 9428)
      • cmd.exe (PID: 9304)
      • cmd.exe (PID: 9332)
      • cmd.exe (PID: 9380)
      • cmd.exe (PID: 9500)
      • cmd.exe (PID: 9524)
      • cmd.exe (PID: 9404)
      • cmd.exe (PID: 9452)
      • cmd.exe (PID: 9476)
      • cmd.exe (PID: 9576)
      • cmd.exe (PID: 9648)
      • cmd.exe (PID: 9624)
      • cmd.exe (PID: 9548)
      • cmd.exe (PID: 9600)
      • cmd.exe (PID: 9720)
      • cmd.exe (PID: 9744)
      • cmd.exe (PID: 9772)
      • cmd.exe (PID: 9696)
      • cmd.exe (PID: 9672)
      • cmd.exe (PID: 9820)
      • cmd.exe (PID: 9796)
      • cmd.exe (PID: 9844)
      • cmd.exe (PID: 9868)
      • cmd.exe (PID: 9892)
      • cmd.exe (PID: 9916)
      • cmd.exe (PID: 9940)
      • cmd.exe (PID: 9964)
      • cmd.exe (PID: 9992)
      • cmd.exe (PID: 10016)
      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 10088)
      • cmd.exe (PID: 10064)
      • cmd.exe (PID: 10112)
      • cmd.exe (PID: 10136)
      • cmd.exe (PID: 10208)
      • cmd.exe (PID: 10232)
      • cmd.exe (PID: 8296)
      • cmd.exe (PID: 10160)
      • cmd.exe (PID: 10184)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 8880)
      • cmd.exe (PID: 9172)
      • cmd.exe (PID: 8464)
      • cmd.exe (PID: 9024)
      • cmd.exe (PID: 9464)
      • cmd.exe (PID: 9756)
      • cmd.exe (PID: 9316)
      • cmd.exe (PID: 9612)
      • cmd.exe (PID: 10196)
      • cmd.exe (PID: 8808)
      • cmd.exe (PID: 9684)
      • cmd.exe (PID: 10124)
      • cmd.exe (PID: 9904)
      • cmd.exe (PID: 10052)
      • cmd.exe (PID: 10360)
      • cmd.exe (PID: 10264)
      • cmd.exe (PID: 10288)
      • cmd.exe (PID: 10312)
      • cmd.exe (PID: 10408)
      • cmd.exe (PID: 10432)
      • cmd.exe (PID: 10456)
      • cmd.exe (PID: 10336)
      • cmd.exe (PID: 10384)
      • cmd.exe (PID: 10528)
      • cmd.exe (PID: 10552)
      • cmd.exe (PID: 10576)
      • cmd.exe (PID: 10480)
      • cmd.exe (PID: 10504)
      • cmd.exe (PID: 10696)
      • cmd.exe (PID: 10672)
      • cmd.exe (PID: 10600)
      • cmd.exe (PID: 10624)
      • cmd.exe (PID: 10648)
      • cmd.exe (PID: 10768)
      • cmd.exe (PID: 10792)
      • cmd.exe (PID: 10816)
      • cmd.exe (PID: 10720)
      • cmd.exe (PID: 10744)
      • cmd.exe (PID: 10888)
      • cmd.exe (PID: 10960)
      • cmd.exe (PID: 10936)
      • cmd.exe (PID: 10840)
      • cmd.exe (PID: 10864)
      • cmd.exe (PID: 10912)
      • cmd.exe (PID: 11056)
      • cmd.exe (PID: 11032)
      • cmd.exe (PID: 11080)
      • cmd.exe (PID: 10984)
      • cmd.exe (PID: 11008)
      • cmd.exe (PID: 11152)
      • cmd.exe (PID: 11176)
      • cmd.exe (PID: 11200)
      • cmd.exe (PID: 11104)
      • cmd.exe (PID: 11128)
      • cmd.exe (PID: 11272)
      • cmd.exe (PID: 11296)
      • cmd.exe (PID: 11320)
      • cmd.exe (PID: 11224)
      • cmd.exe (PID: 11248)
      • cmd.exe (PID: 11412)
      • cmd.exe (PID: 11436)
      • cmd.exe (PID: 11460)
      • cmd.exe (PID: 11364)
      • cmd.exe (PID: 11388)
      • cmd.exe (PID: 11532)
      • cmd.exe (PID: 11484)
      • cmd.exe (PID: 11508)
      • cmd.exe (PID: 11556)
      • cmd.exe (PID: 11580)
      • cmd.exe (PID: 11604)
      • cmd.exe (PID: 11628)
      • cmd.exe (PID: 11652)
      • cmd.exe (PID: 11676)
      • cmd.exe (PID: 11700)
      • cmd.exe (PID: 11724)
      • cmd.exe (PID: 11748)
    • Application launched itself

      • cmd.exe (PID: 3156)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 3220)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 3524)
      • cmd.exe (PID: 3576)
      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 3632)
      • cmd.exe (PID: 3596)
      • cmd.exe (PID: 3464)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 3812)
      • cmd.exe (PID: 3928)
      • cmd.exe (PID: 3660)
      • cmd.exe (PID: 3852)
      • cmd.exe (PID: 3752)
      • cmd.exe (PID: 4020)
      • cmd.exe (PID: 4064)
      • cmd.exe (PID: 3972)
      • cmd.exe (PID: 3908)
      • cmd.exe (PID: 3748)
      • cmd.exe (PID: 4048)
      • cmd.exe (PID: 4088)
      • cmd.exe (PID: 4068)
      • cmd.exe (PID: 3696)
      • cmd.exe (PID: 3672)
      • cmd.exe (PID: 4060)
      • cmd.exe (PID: 3820)
      • cmd.exe (PID: 2060)
      • cmd.exe (PID: 1628)
      • cmd.exe (PID: 1808)
      • cmd.exe (PID: 608)
      • cmd.exe (PID: 316)
      • cmd.exe (PID: 1152)
      • cmd.exe (PID: 1360)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 2164)
      • cmd.exe (PID: 1272)
      • cmd.exe (PID: 1904)
      • cmd.exe (PID: 1812)
      • cmd.exe (PID: 1236)
      • cmd.exe (PID: 2392)
      • cmd.exe (PID: 1644)
      • cmd.exe (PID: 2632)
      • cmd.exe (PID: 2300)
      • cmd.exe (PID: 2328)
      • cmd.exe (PID: 3800)
      • cmd.exe (PID: 1036)
      • cmd.exe (PID: 2724)
      • cmd.exe (PID: 2560)
      • cmd.exe (PID: 3796)
      • cmd.exe (PID: 1088)
      • cmd.exe (PID: 1584)
      • cmd.exe (PID: 2400)
      • cmd.exe (PID: 280)
      • cmd.exe (PID: 2176)
      • cmd.exe (PID: 2120)
      • cmd.exe (PID: 1700)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 3044)
      • cmd.exe (PID: 3048)
      • cmd.exe (PID: 2836)
      • cmd.exe (PID: 2232)
      • cmd.exe (PID: 2692)
      • cmd.exe (PID: 880)
      • cmd.exe (PID: 2908)
      • cmd.exe (PID: 888)
      • cmd.exe (PID: 372)
      • cmd.exe (PID: 3012)
      • cmd.exe (PID: 3316)
      • cmd.exe (PID: 3052)
      • cmd.exe (PID: 3056)
      • cmd.exe (PID: 3128)
      • cmd.exe (PID: 2976)
      • cmd.exe (PID: 2436)
      • cmd.exe (PID: 3420)
      • cmd.exe (PID: 3724)
      • cmd.exe (PID: 3592)
      • cmd.exe (PID: 3216)
      • cmd.exe (PID: 3876)
      • cmd.exe (PID: 2684)
      • cmd.exe (PID: 1696)
      • cmd.exe (PID: 3816)
      • cmd.exe (PID: 3868)
      • cmd.exe (PID: 1436)
      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 1880)
      • cmd.exe (PID: 4148)
      • cmd.exe (PID: 2516)
      • cmd.exe (PID: 2860)
      • cmd.exe (PID: 4100)
      • cmd.exe (PID: 4124)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 2116)
      • cmd.exe (PID: 4220)
      • cmd.exe (PID: 4196)
      • cmd.exe (PID: 4244)
      • cmd.exe (PID: 4268)
      • cmd.exe (PID: 4172)
      • cmd.exe (PID: 4340)
      • cmd.exe (PID: 4388)
      • cmd.exe (PID: 4412)
      • cmd.exe (PID: 4292)
      • cmd.exe (PID: 4316)
      • cmd.exe (PID: 4364)
      • cmd.exe (PID: 4484)
      • cmd.exe (PID: 4508)
      • cmd.exe (PID: 4532)
      • cmd.exe (PID: 4436)
      • cmd.exe (PID: 4460)
      • cmd.exe (PID: 4636)
      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 4556)
      • cmd.exe (PID: 4588)
      • cmd.exe (PID: 4612)
      • cmd.exe (PID: 4756)
      • cmd.exe (PID: 4780)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 4684)
      • cmd.exe (PID: 4708)
      • cmd.exe (PID: 4732)
      • cmd.exe (PID: 4852)
      • cmd.exe (PID: 4876)
      • cmd.exe (PID: 4948)
      • cmd.exe (PID: 4924)
      • cmd.exe (PID: 4828)
      • cmd.exe (PID: 4900)
      • cmd.exe (PID: 4972)
      • cmd.exe (PID: 4996)
      • cmd.exe (PID: 5020)
      • cmd.exe (PID: 5044)
      • cmd.exe (PID: 5116)
      • cmd.exe (PID: 5068)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 5140)
      • cmd.exe (PID: 5164)
      • cmd.exe (PID: 5188)
      • cmd.exe (PID: 5212)
      • cmd.exe (PID: 5236)
      • cmd.exe (PID: 5260)
      • cmd.exe (PID: 5284)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5332)
      • cmd.exe (PID: 5356)
      • cmd.exe (PID: 5380)
      • cmd.exe (PID: 5404)
      • cmd.exe (PID: 5428)
      • cmd.exe (PID: 5452)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5524)
      • cmd.exe (PID: 5572)
      • cmd.exe (PID: 5476)
      • cmd.exe (PID: 5500)
      • cmd.exe (PID: 5668)
      • cmd.exe (PID: 5692)
      • cmd.exe (PID: 5596)
      • cmd.exe (PID: 5620)
      • cmd.exe (PID: 5644)
      • cmd.exe (PID: 5764)
      • cmd.exe (PID: 5812)
      • cmd.exe (PID: 5836)
      • cmd.exe (PID: 5716)
      • cmd.exe (PID: 5740)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 5884)
      • cmd.exe (PID: 5908)
      • cmd.exe (PID: 5932)
      • cmd.exe (PID: 5956)
      • cmd.exe (PID: 5860)
      • cmd.exe (PID: 6028)
      • cmd.exe (PID: 6052)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 5980)
      • cmd.exe (PID: 6004)
      • cmd.exe (PID: 4136)
      • cmd.exe (PID: 4280)
      • cmd.exe (PID: 3684)
      • cmd.exe (PID: 6100)
      • cmd.exe (PID: 6124)
      • cmd.exe (PID: 4424)
      • cmd.exe (PID: 4816)
      • cmd.exe (PID: 4960)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 5224)
      • cmd.exe (PID: 5368)
      • cmd.exe (PID: 4584)
      • cmd.exe (PID: 4672)
      • cmd.exe (PID: 2808)
      • cmd.exe (PID: 6064)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 5632)
      • cmd.exe (PID: 5776)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 5152)
      • cmd.exe (PID: 4496)
      • cmd.exe (PID: 6156)
      • cmd.exe (PID: 6180)
      • cmd.exe (PID: 6204)
      • cmd.exe (PID: 6232)
      • cmd.exe (PID: 6256)
      • cmd.exe (PID: 6280)
      • cmd.exe (PID: 6304)
      • cmd.exe (PID: 6328)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6376)
      • cmd.exe (PID: 6400)
      • cmd.exe (PID: 6500)
      • cmd.exe (PID: 6524)
      • cmd.exe (PID: 6548)
      • cmd.exe (PID: 6428)
      • cmd.exe (PID: 6452)
      • cmd.exe (PID: 6476)
      • cmd.exe (PID: 6620)
      • cmd.exe (PID: 6644)
      • cmd.exe (PID: 6668)
      • cmd.exe (PID: 6572)
      • cmd.exe (PID: 6596)
      • cmd.exe (PID: 6764)
      • cmd.exe (PID: 6740)
      • cmd.exe (PID: 6788)
      • cmd.exe (PID: 6812)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 6716)
      • cmd.exe (PID: 6912)
      • cmd.exe (PID: 6864)
      • cmd.exe (PID: 6888)
      • cmd.exe (PID: 6960)
      • cmd.exe (PID: 6936)
      • cmd.exe (PID: 6840)
      • cmd.exe (PID: 7056)
      • cmd.exe (PID: 7032)
      • cmd.exe (PID: 7080)
      • cmd.exe (PID: 6984)
      • cmd.exe (PID: 7008)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 7128)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 7176)
      • cmd.exe (PID: 7252)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7328)
      • cmd.exe (PID: 7352)
      • cmd.exe (PID: 7280)
      • cmd.exe (PID: 7400)
      • cmd.exe (PID: 7448)
      • cmd.exe (PID: 7424)
      • cmd.exe (PID: 7472)
      • cmd.exe (PID: 7496)
      • cmd.exe (PID: 7376)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7572)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7620)
      • cmd.exe (PID: 7520)
      • cmd.exe (PID: 7644)
      • cmd.exe (PID: 7740)
      • cmd.exe (PID: 7716)
      • cmd.exe (PID: 7764)
      • cmd.exe (PID: 7668)
      • cmd.exe (PID: 7692)
      • cmd.exe (PID: 7812)
      • cmd.exe (PID: 7840)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 7888)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 8084)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 8036)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 8156)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 6216)
      • cmd.exe (PID: 6656)
      • cmd.exe (PID: 6800)
      • cmd.exe (PID: 6948)
      • cmd.exe (PID: 7092)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 7532)
      • cmd.exe (PID: 7680)
      • cmd.exe (PID: 7240)
      • cmd.exe (PID: 7364)
      • cmd.exe (PID: 6584)
      • cmd.exe (PID: 7020)
      • cmd.exe (PID: 7436)
      • cmd.exe (PID: 7824)
      • cmd.exe (PID: 7976)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 8208)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 8284)
      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8404)
      • cmd.exe (PID: 8308)
      • cmd.exe (PID: 8332)
      • cmd.exe (PID: 8476)
      • cmd.exe (PID: 8500)
      • cmd.exe (PID: 8428)
      • cmd.exe (PID: 8452)
      • cmd.exe (PID: 8600)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 8528)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 8576)
      • cmd.exe (PID: 8648)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 8768)
      • cmd.exe (PID: 8796)
      • cmd.exe (PID: 8696)
      • cmd.exe (PID: 8868)
      • cmd.exe (PID: 8892)
      • cmd.exe (PID: 8916)
      • cmd.exe (PID: 8820)
      • cmd.exe (PID: 8844)
      • cmd.exe (PID: 8940)
      • cmd.exe (PID: 8964)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 9012)
      • cmd.exe (PID: 9036)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 9136)
      • cmd.exe (PID: 9184)
      • cmd.exe (PID: 9084)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9256)
      • cmd.exe (PID: 9280)
      • cmd.exe (PID: 9304)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 9232)
      • cmd.exe (PID: 9356)
      • cmd.exe (PID: 9332)
      • cmd.exe (PID: 9380)
      • cmd.exe (PID: 9452)
      • cmd.exe (PID: 9404)
      • cmd.exe (PID: 9476)
      • cmd.exe (PID: 9500)
      • cmd.exe (PID: 9428)
      • cmd.exe (PID: 9576)
      • cmd.exe (PID: 9600)
      • cmd.exe (PID: 9648)
      • cmd.exe (PID: 9524)
      • cmd.exe (PID: 9548)
      • cmd.exe (PID: 9624)
      • cmd.exe (PID: 9720)
      • cmd.exe (PID: 9744)
      • cmd.exe (PID: 9796)
      • cmd.exe (PID: 9772)
      • cmd.exe (PID: 9672)
      • cmd.exe (PID: 9696)
      • cmd.exe (PID: 9844)
      • cmd.exe (PID: 9820)
      • cmd.exe (PID: 9868)
      • cmd.exe (PID: 9892)
      • cmd.exe (PID: 9940)
      • cmd.exe (PID: 9916)
      • cmd.exe (PID: 9964)
      • cmd.exe (PID: 10016)
      • cmd.exe (PID: 9992)
      • cmd.exe (PID: 10088)
      • cmd.exe (PID: 10112)
      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 10064)
      • cmd.exe (PID: 10208)
      • cmd.exe (PID: 10232)
      • cmd.exe (PID: 8296)
      • cmd.exe (PID: 10136)
      • cmd.exe (PID: 10160)
      • cmd.exe (PID: 10184)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 8880)
      • cmd.exe (PID: 9024)
      • cmd.exe (PID: 8464)
      • cmd.exe (PID: 9316)
      • cmd.exe (PID: 9756)
      • cmd.exe (PID: 9612)
      • cmd.exe (PID: 9904)
      • cmd.exe (PID: 9172)
      • cmd.exe (PID: 9464)
      • cmd.exe (PID: 10196)
      • cmd.exe (PID: 8808)
      • cmd.exe (PID: 9684)
      • cmd.exe (PID: 10052)
      • cmd.exe (PID: 10312)
      • cmd.exe (PID: 10124)
      • cmd.exe (PID: 10264)
      • cmd.exe (PID: 10288)
      • cmd.exe (PID: 10432)
      • cmd.exe (PID: 10456)
      • cmd.exe (PID: 10360)
      • cmd.exe (PID: 10336)
      • cmd.exe (PID: 10384)
      • cmd.exe (PID: 10408)
      • cmd.exe (PID: 10528)
      • cmd.exe (PID: 10552)
      • cmd.exe (PID: 10576)
      • cmd.exe (PID: 10480)
      • cmd.exe (PID: 10504)
      • cmd.exe (PID: 10648)
      • cmd.exe (PID: 10672)
      • cmd.exe (PID: 10696)
      • cmd.exe (PID: 10600)
      • cmd.exe (PID: 10624)
      • cmd.exe (PID: 10744)
      • cmd.exe (PID: 10792)
      • cmd.exe (PID: 10768)
      • cmd.exe (PID: 10840)
      • cmd.exe (PID: 10720)
      • cmd.exe (PID: 10816)
      • cmd.exe (PID: 10912)
      • cmd.exe (PID: 10936)
      • cmd.exe (PID: 10864)
      • cmd.exe (PID: 10888)
      • cmd.exe (PID: 11032)
      • cmd.exe (PID: 11056)
      • cmd.exe (PID: 11080)
      • cmd.exe (PID: 10960)
      • cmd.exe (PID: 10984)
      • cmd.exe (PID: 11008)
      • cmd.exe (PID: 11176)
      • cmd.exe (PID: 11200)
      • cmd.exe (PID: 11224)
      • cmd.exe (PID: 11104)
      • cmd.exe (PID: 11128)
      • cmd.exe (PID: 11152)
      • cmd.exe (PID: 11272)
      • cmd.exe (PID: 11296)
      • cmd.exe (PID: 11320)
      • cmd.exe (PID: 11364)
      • cmd.exe (PID: 11248)
      • cmd.exe (PID: 11412)
      • cmd.exe (PID: 11436)
      • cmd.exe (PID: 11460)
      • cmd.exe (PID: 11388)
      • cmd.exe (PID: 11484)
      • cmd.exe (PID: 11508)
      • cmd.exe (PID: 11532)
      • cmd.exe (PID: 11556)
      • cmd.exe (PID: 11580)
      • cmd.exe (PID: 11604)
      • cmd.exe (PID: 11628)
      • cmd.exe (PID: 11652)
      • cmd.exe (PID: 11676)
      • cmd.exe (PID: 11700)
      • cmd.exe (PID: 11724)
      • cmd.exe (PID: 11748)
    • Executing commands from a ".bat" file

      • cmd.exe (PID: 3156)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 3220)
      • cmd.exe (PID: 2904)
      • cmd.exe (PID: 3124)
      • cmd.exe (PID: 3276)
      • cmd.exe (PID: 3576)
      • cmd.exe (PID: 3524)
      • cmd.exe (PID: 3464)
      • cmd.exe (PID: 3596)
      • cmd.exe (PID: 3856)
      • cmd.exe (PID: 3852)
      • cmd.exe (PID: 3812)
      • cmd.exe (PID: 3928)
      • cmd.exe (PID: 3632)
      • cmd.exe (PID: 3660)
      • cmd.exe (PID: 3752)
      • cmd.exe (PID: 4020)
      • cmd.exe (PID: 3972)
      • cmd.exe (PID: 3908)
      • cmd.exe (PID: 3748)
      • cmd.exe (PID: 4088)
      • cmd.exe (PID: 4048)
      • cmd.exe (PID: 4068)
      • cmd.exe (PID: 3696)
      • cmd.exe (PID: 4064)
      • cmd.exe (PID: 4060)
      • cmd.exe (PID: 2060)
      • cmd.exe (PID: 1808)
      • cmd.exe (PID: 608)
      • cmd.exe (PID: 3672)
      • cmd.exe (PID: 3820)
      • cmd.exe (PID: 1628)
      • cmd.exe (PID: 316)
      • cmd.exe (PID: 1152)
      • cmd.exe (PID: 1360)
      • cmd.exe (PID: 1856)
      • cmd.exe (PID: 2164)
      • cmd.exe (PID: 1904)
      • cmd.exe (PID: 1272)
      • cmd.exe (PID: 1236)
      • cmd.exe (PID: 1812)
      • cmd.exe (PID: 2392)
      • cmd.exe (PID: 1644)
      • cmd.exe (PID: 1036)
      • cmd.exe (PID: 2300)
      • cmd.exe (PID: 2328)
      • cmd.exe (PID: 3800)
      • cmd.exe (PID: 2560)
      • cmd.exe (PID: 2724)
      • cmd.exe (PID: 1088)
      • cmd.exe (PID: 3796)
      • cmd.exe (PID: 1584)
      • cmd.exe (PID: 1700)
      • cmd.exe (PID: 2632)
      • cmd.exe (PID: 280)
      • cmd.exe (PID: 2176)
      • cmd.exe (PID: 2120)
      • cmd.exe (PID: 2400)
      • cmd.exe (PID: 2836)
      • cmd.exe (PID: 604)
      • cmd.exe (PID: 2692)
      • cmd.exe (PID: 3044)
      • cmd.exe (PID: 2232)
      • cmd.exe (PID: 2512)
      • cmd.exe (PID: 3012)
      • cmd.exe (PID: 2908)
      • cmd.exe (PID: 888)
      • cmd.exe (PID: 372)
      • cmd.exe (PID: 3048)
      • cmd.exe (PID: 880)
      • cmd.exe (PID: 3316)
      • cmd.exe (PID: 3052)
      • cmd.exe (PID: 3056)
      • cmd.exe (PID: 2976)
      • cmd.exe (PID: 2436)
      • cmd.exe (PID: 3724)
      • cmd.exe (PID: 3592)
      • cmd.exe (PID: 3128)
      • cmd.exe (PID: 3216)
      • cmd.exe (PID: 3420)
      • cmd.exe (PID: 3876)
      • cmd.exe (PID: 1880)
      • cmd.exe (PID: 1696)
      • cmd.exe (PID: 3816)
      • cmd.exe (PID: 2684)
      • cmd.exe (PID: 3868)
      • cmd.exe (PID: 1436)
      • cmd.exe (PID: 1208)
      • cmd.exe (PID: 4100)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 2116)
      • cmd.exe (PID: 2860)
      • cmd.exe (PID: 4124)
      • cmd.exe (PID: 2516)
      • cmd.exe (PID: 4172)
      • cmd.exe (PID: 4220)
      • cmd.exe (PID: 4244)
      • cmd.exe (PID: 4268)
      • cmd.exe (PID: 4148)
      • cmd.exe (PID: 4196)
      • cmd.exe (PID: 4316)
      • cmd.exe (PID: 4388)
      • cmd.exe (PID: 4340)
      • cmd.exe (PID: 4364)
      • cmd.exe (PID: 4412)
      • cmd.exe (PID: 4292)
      • cmd.exe (PID: 4460)
      • cmd.exe (PID: 4484)
      • cmd.exe (PID: 4508)
      • cmd.exe (PID: 4532)
      • cmd.exe (PID: 4556)
      • cmd.exe (PID: 4436)
      • cmd.exe (PID: 4588)
      • cmd.exe (PID: 4612)
      • cmd.exe (PID: 4636)
      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 4684)
      • cmd.exe (PID: 4732)
      • cmd.exe (PID: 4780)
      • cmd.exe (PID: 4804)
      • cmd.exe (PID: 4708)
      • cmd.exe (PID: 4756)
      • cmd.exe (PID: 4876)
      • cmd.exe (PID: 4900)
      • cmd.exe (PID: 4924)
      • cmd.exe (PID: 4828)
      • cmd.exe (PID: 4852)
      • cmd.exe (PID: 5044)
      • cmd.exe (PID: 4948)
      • cmd.exe (PID: 4972)
      • cmd.exe (PID: 4996)
      • cmd.exe (PID: 5020)
      • cmd.exe (PID: 5116)
      • cmd.exe (PID: 5068)
      • cmd.exe (PID: 5092)
      • cmd.exe (PID: 5140)
      • cmd.exe (PID: 5164)
      • cmd.exe (PID: 5188)
      • cmd.exe (PID: 5212)
      • cmd.exe (PID: 5236)
      • cmd.exe (PID: 5260)
      • cmd.exe (PID: 5284)
      • cmd.exe (PID: 5308)
      • cmd.exe (PID: 5332)
      • cmd.exe (PID: 5428)
      • cmd.exe (PID: 5452)
      • cmd.exe (PID: 5356)
      • cmd.exe (PID: 5380)
      • cmd.exe (PID: 5404)
      • cmd.exe (PID: 5524)
      • cmd.exe (PID: 5572)
      • cmd.exe (PID: 5548)
      • cmd.exe (PID: 5476)
      • cmd.exe (PID: 5500)
      • cmd.exe (PID: 5644)
      • cmd.exe (PID: 5668)
      • cmd.exe (PID: 5692)
      • cmd.exe (PID: 5716)
      • cmd.exe (PID: 5596)
      • cmd.exe (PID: 5620)
      • cmd.exe (PID: 5788)
      • cmd.exe (PID: 5836)
      • cmd.exe (PID: 5740)
      • cmd.exe (PID: 5764)
      • cmd.exe (PID: 5812)
      • cmd.exe (PID: 5908)
      • cmd.exe (PID: 5932)
      • cmd.exe (PID: 5956)
      • cmd.exe (PID: 5860)
      • cmd.exe (PID: 5884)
      • cmd.exe (PID: 6004)
      • cmd.exe (PID: 6100)
      • cmd.exe (PID: 6028)
      • cmd.exe (PID: 6052)
      • cmd.exe (PID: 6076)
      • cmd.exe (PID: 5980)
      • cmd.exe (PID: 4136)
      • cmd.exe (PID: 4280)
      • cmd.exe (PID: 4424)
      • cmd.exe (PID: 3684)
      • cmd.exe (PID: 6124)
      • cmd.exe (PID: 4816)
      • cmd.exe (PID: 5224)
      • cmd.exe (PID: 2344)
      • cmd.exe (PID: 4584)
      • cmd.exe (PID: 4672)
      • cmd.exe (PID: 4960)
      • cmd.exe (PID: 5368)
      • cmd.exe (PID: 2808)
      • cmd.exe (PID: 5632)
      • cmd.exe (PID: 5776)
      • cmd.exe (PID: 6064)
      • cmd.exe (PID: 5920)
      • cmd.exe (PID: 4496)
      • cmd.exe (PID: 5152)
      • cmd.exe (PID: 5992)
      • cmd.exe (PID: 6156)
      • cmd.exe (PID: 6180)
      • cmd.exe (PID: 6204)
      • cmd.exe (PID: 6232)
      • cmd.exe (PID: 6256)
      • cmd.exe (PID: 6280)
      • cmd.exe (PID: 6428)
      • cmd.exe (PID: 6304)
      • cmd.exe (PID: 6328)
      • cmd.exe (PID: 6352)
      • cmd.exe (PID: 6376)
      • cmd.exe (PID: 6400)
      • cmd.exe (PID: 6476)
      • cmd.exe (PID: 6500)
      • cmd.exe (PID: 6524)
      • cmd.exe (PID: 6452)
      • cmd.exe (PID: 6644)
      • cmd.exe (PID: 6596)
      • cmd.exe (PID: 6668)
      • cmd.exe (PID: 6548)
      • cmd.exe (PID: 6572)
      • cmd.exe (PID: 6620)
      • cmd.exe (PID: 6716)
      • cmd.exe (PID: 6740)
      • cmd.exe (PID: 6764)
      • cmd.exe (PID: 6788)
      • cmd.exe (PID: 6812)
      • cmd.exe (PID: 6692)
      • cmd.exe (PID: 6840)
      • cmd.exe (PID: 6864)
      • cmd.exe (PID: 6936)
      • cmd.exe (PID: 6960)
      • cmd.exe (PID: 6888)
      • cmd.exe (PID: 6912)
      • cmd.exe (PID: 7008)
      • cmd.exe (PID: 7032)
      • cmd.exe (PID: 7056)
      • cmd.exe (PID: 7080)
      • cmd.exe (PID: 6984)
      • cmd.exe (PID: 7152)
      • cmd.exe (PID: 7176)
      • cmd.exe (PID: 7200)
      • cmd.exe (PID: 7104)
      • cmd.exe (PID: 7128)
      • cmd.exe (PID: 7280)
      • cmd.exe (PID: 7304)
      • cmd.exe (PID: 7376)
      • cmd.exe (PID: 7228)
      • cmd.exe (PID: 7252)
      • cmd.exe (PID: 7328)
      • cmd.exe (PID: 7352)
      • cmd.exe (PID: 7424)
      • cmd.exe (PID: 7472)
      • cmd.exe (PID: 7496)
      • cmd.exe (PID: 7400)
      • cmd.exe (PID: 7448)
      • cmd.exe (PID: 7544)
      • cmd.exe (PID: 7572)
      • cmd.exe (PID: 7596)
      • cmd.exe (PID: 7620)
      • cmd.exe (PID: 7520)
      • cmd.exe (PID: 7692)
      • cmd.exe (PID: 7716)
      • cmd.exe (PID: 7740)
      • cmd.exe (PID: 7644)
      • cmd.exe (PID: 7668)
      • cmd.exe (PID: 7812)
      • cmd.exe (PID: 7840)
      • cmd.exe (PID: 7764)
      • cmd.exe (PID: 7788)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 7988)
      • cmd.exe (PID: 8012)
      • cmd.exe (PID: 7888)
      • cmd.exe (PID: 7912)
      • cmd.exe (PID: 7936)
      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 8060)
      • cmd.exe (PID: 8036)
      • cmd.exe (PID: 8108)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 6216)
      • cmd.exe (PID: 8084)
      • cmd.exe (PID: 8132)
      • cmd.exe (PID: 8156)
      • cmd.exe (PID: 6800)
      • cmd.exe (PID: 6948)
      • cmd.exe (PID: 6364)
      • cmd.exe (PID: 6512)
      • cmd.exe (PID: 6656)
      • cmd.exe (PID: 7532)
      • cmd.exe (PID: 7680)
      • cmd.exe (PID: 7824)
      • cmd.exe (PID: 7092)
      • cmd.exe (PID: 7240)
      • cmd.exe (PID: 7364)
      • cmd.exe (PID: 6584)
      • cmd.exe (PID: 7436)
      • cmd.exe (PID: 7976)
      • cmd.exe (PID: 8120)
      • cmd.exe (PID: 8236)
      • cmd.exe (PID: 8284)
      • cmd.exe (PID: 8260)
      • cmd.exe (PID: 7020)
      • cmd.exe (PID: 3356)
      • cmd.exe (PID: 8208)
      • cmd.exe (PID: 8356)
      • cmd.exe (PID: 8380)
      • cmd.exe (PID: 8404)
      • cmd.exe (PID: 8308)
      • cmd.exe (PID: 8332)
      • cmd.exe (PID: 8528)
      • cmd.exe (PID: 8476)
      • cmd.exe (PID: 8500)
      • cmd.exe (PID: 8428)
      • cmd.exe (PID: 8452)
      • cmd.exe (PID: 8600)
      • cmd.exe (PID: 8648)
      • cmd.exe (PID: 8624)
      • cmd.exe (PID: 8552)
      • cmd.exe (PID: 8576)
      • cmd.exe (PID: 8696)
      • cmd.exe (PID: 8720)
      • cmd.exe (PID: 8796)
      • cmd.exe (PID: 8672)
      • cmd.exe (PID: 8744)
      • cmd.exe (PID: 8768)
      • cmd.exe (PID: 8844)
      • cmd.exe (PID: 8892)
      • cmd.exe (PID: 8916)
      • cmd.exe (PID: 8820)
      • cmd.exe (PID: 8868)
      • cmd.exe (PID: 8988)
      • cmd.exe (PID: 9012)
      • cmd.exe (PID: 9036)
      • cmd.exe (PID: 8940)
      • cmd.exe (PID: 8964)
      • cmd.exe (PID: 9108)
      • cmd.exe (PID: 9136)
      • cmd.exe (PID: 9160)
      • cmd.exe (PID: 9060)
      • cmd.exe (PID: 9084)
      • cmd.exe (PID: 9256)
      • cmd.exe (PID: 9280)
      • cmd.exe (PID: 9304)
      • cmd.exe (PID: 9184)
      • cmd.exe (PID: 9208)
      • cmd.exe (PID: 9232)
      • cmd.exe (PID: 9380)
      • cmd.exe (PID: 9332)
      • cmd.exe (PID: 9356)
      • cmd.exe (PID: 9524)
      • cmd.exe (PID: 9500)
      • cmd.exe (PID: 9452)
      • cmd.exe (PID: 9404)
      • cmd.exe (PID: 9428)
      • cmd.exe (PID: 9476)
      • cmd.exe (PID: 9600)
      • cmd.exe (PID: 9648)
      • cmd.exe (PID: 9624)
      • cmd.exe (PID: 9548)
      • cmd.exe (PID: 9576)
      • cmd.exe (PID: 9696)
      • cmd.exe (PID: 9744)
      • cmd.exe (PID: 9720)
      • cmd.exe (PID: 9772)
      • cmd.exe (PID: 9672)
      • cmd.exe (PID: 9796)
      • cmd.exe (PID: 9820)
      • cmd.exe (PID: 9844)
      • cmd.exe (PID: 9868)
      • cmd.exe (PID: 9892)
      • cmd.exe (PID: 9916)
      • cmd.exe (PID: 9940)
      • cmd.exe (PID: 9964)
      • cmd.exe (PID: 9992)
      • cmd.exe (PID: 10016)
      • cmd.exe (PID: 10040)
      • cmd.exe (PID: 10064)
      • cmd.exe (PID: 10088)
      • cmd.exe (PID: 10136)
      • cmd.exe (PID: 10112)
      • cmd.exe (PID: 10184)
      • cmd.exe (PID: 10232)
      • cmd.exe (PID: 8296)
      • cmd.exe (PID: 10160)
      • cmd.exe (PID: 10208)
      • cmd.exe (PID: 8756)
      • cmd.exe (PID: 8880)
      • cmd.exe (PID: 8464)
      • cmd.exe (PID: 8612)
      • cmd.exe (PID: 9024)
      • cmd.exe (PID: 9464)
      • cmd.exe (PID: 9756)
      • cmd.exe (PID: 9904)
      • cmd.exe (PID: 9316)
      • cmd.exe (PID: 9172)
      • cmd.exe (PID: 9612)
      • cmd.exe (PID: 10196)
      • cmd.exe (PID: 9684)
      • cmd.exe (PID: 10052)
      • cmd.exe (PID: 8808)
      • cmd.exe (PID: 10336)
      • cmd.exe (PID: 10360)
      • cmd.exe (PID: 10264)
      • cmd.exe (PID: 10124)
      • cmd.exe (PID: 10288)
      • cmd.exe (PID: 10432)
      • cmd.exe (PID: 10456)
      • cmd.exe (PID: 10384)
      • cmd.exe (PID: 10312)
      • cmd.exe (PID: 10408)
      • cmd.exe (PID: 10528)
      • cmd.exe (PID: 10552)
      • cmd.exe (PID: 10480)
      • cmd.exe (PID: 10504)
      • cmd.exe (PID: 10576)
      • cmd.exe (PID: 10672)
      • cmd.exe (PID: 10696)
      • cmd.exe (PID: 10600)
      • cmd.exe (PID: 10624)
      • cmd.exe (PID: 10648)
      • cmd.exe (PID: 10792)
      • cmd.exe (PID: 10720)
      • cmd.exe (PID: 10744)
      • cmd.exe (PID: 10768)
      • cmd.exe (PID: 10816)
      • cmd.exe (PID: 10960)
      • cmd.exe (PID: 10936)
      • cmd.exe (PID: 10912)
      • cmd.exe (PID: 10840)
      • cmd.exe (PID: 10864)
      • cmd.exe (PID: 10888)
      • cmd.exe (PID: 11008)
      • cmd.exe (PID: 11056)
      • cmd.exe (PID: 11080)
      • cmd.exe (PID: 10984)
      • cmd.exe (PID: 11032)
      • cmd.exe (PID: 11128)
      • cmd.exe (PID: 11152)
      • cmd.exe (PID: 11200)
      • cmd.exe (PID: 11104)
      • cmd.exe (PID: 11176)
      • cmd.exe (PID: 11248)
      • cmd.exe (PID: 11320)
      • cmd.exe (PID: 11364)
      • cmd.exe (PID: 11224)
      • cmd.exe (PID: 11272)
      • cmd.exe (PID: 11296)
      • cmd.exe (PID: 11460)
      • cmd.exe (PID: 11436)
      • cmd.exe (PID: 11388)
      • cmd.exe (PID: 11412)
      • cmd.exe (PID: 11484)
      • cmd.exe (PID: 11508)
      • cmd.exe (PID: 11532)
      • cmd.exe (PID: 11556)
      • cmd.exe (PID: 11580)
      • cmd.exe (PID: 11604)
      • cmd.exe (PID: 11628)
      • cmd.exe (PID: 11652)
      • cmd.exe (PID: 11676)
      • cmd.exe (PID: 11700)
      • cmd.exe (PID: 11724)
      • cmd.exe (PID: 11748)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
961
Monitored processes
463
Malicious processes
455
Suspicious processes
6

Behavior graph

Click at the process to see the details
start cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
316C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
372C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
604C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
608C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
880C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
888C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1036C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1088C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1152C:\Windows\system32\cmd.exe /K instance.bat C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
7 392
Read events
7 392
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3436cmd.exeC:\Users\admin\Desktop\instance.battext
MD5:8E0703A115A21D2A97FB5A9FEAE05368
SHA256:FD4A20319EB08CCA18CF4F3C67DE30DEE21C7D9B4EDEEC8CC9C9E11672B14ACE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info