Analysis
-
max time kernel
150s -
max time network
122s -
platform
windows7_x64 -
resource
win7-20240508-en -
resource tags
arch:x64arch:x86image:win7-20240508-enlocale:en-usos:windows7-x64system -
submitted
28-06-2024 06:34
Behavioral task
behavioral1
Sample
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Resource
win10v2004-20240611-en
General
-
Target
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
-
Size
68KB
-
MD5
19224d8fe2957721118d14faef5096ce
-
SHA1
2438ee98bc8a07143c6e64c7a1bcb1386878baa3
-
SHA256
fb4aef1c345a246ca40f7629e3a760a69e7a84161995286cda1fd26aa74c3ae9
-
SHA512
867d2e0d94ab71c4d6eb2ec9df1c79ebbca8b6d3db8c0f58cf27bb1ea852c0caed39fe058f0ed194df41354177881ee2d8ae4d9c59b10c3afbcb17a3425833de
-
SSDEEP
1536:p4jqi5axwdaPpyNlDgS54QuZxDuKTVWCrx4LTT61B8:ujpaxGaPpyNV54DyiVd12
Malware Config
Signatures
-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage 10 IoCs
Processes:
resource yara_rule behavioral1/memory/2244-4-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2092-13-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2644-22-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2524-28-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2296-34-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2688-40-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2588-46-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/1280-52-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2176-58-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral1/memory/2716-64-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 -
Suspicious use of SetThreadContext 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process target process PID 2244 set thread context of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 set thread context of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 set thread context of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 set thread context of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 set thread context of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 set thread context of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2588 set thread context of 2636 2588 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1280 set thread context of 2964 1280 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2176 set thread context of 560 2176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2716 set thread context of 1956 2716 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1228 set thread context of 336 1228 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1988 set thread context of 1852 1988 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2440 set thread context of 1048 2440 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2480 set thread context of 1196 2480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2816 set thread context of 2344 2816 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2612 set thread context of 2500 2612 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2896 set thread context of 2496 2896 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 484 set thread context of 788 484 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1480 set thread context of 1776 1480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1812 set thread context of 1576 1812 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2336 set thread context of 2360 2336 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1524 set thread context of 1368 1524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1632 set thread context of 1644 1632 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 900 set thread context of 620 900 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2904 set thread context of 2116 2904 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2980 set thread context of 2036 2980 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 876 set thread context of 2148 876 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2060 set thread context of 1184 2060 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2836 set thread context of 2824 2836 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1700 set thread context of 2768 1700 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2764 set thread context of 2640 2764 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2784 set thread context of 2756 2784 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2544 set thread context of 2652 2544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2548 set thread context of 2532 2548 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2136 set thread context of 2008 2136 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2404 set thread context of 2204 2404 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2176 set thread context of 1672 2176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2444 set thread context of 2164 2444 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1224 set thread context of 1868 1224 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1932 set thread context of 1664 1932 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2440 set thread context of 1248 2440 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1544 set thread context of 2804 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2816 set thread context of 2368 2816 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1260 set thread context of 2108 1260 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2896 set thread context of 2152 2896 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1300 set thread context of 1488 1300 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 788 set thread context of 1480 788 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1776 set thread context of 828 1776 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1576 set thread context of 2336 1576 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2360 set thread context of 1524 2360 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1996 set thread context of 2076 1996 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 656 set thread context of 752 656 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1316 set thread context of 620 1316 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1512 set thread context of 852 1512 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 884 set thread context of 2036 884 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1720 set thread context of 2104 1720 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1816 set thread context of 1184 1816 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2700 set thread context of 2824 2700 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2828 set thread context of 2768 2828 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2868 set thread context of 2648 2868 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2540 set thread context of 2756 2540 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2516 set thread context of 2680 2516 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2948 set thread context of 2532 2948 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2224 set thread context of 2028 2224 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process Token: SeIncBasePriorityPrivilege 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2972 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2604 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2628 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2636 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2964 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 560 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1956 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 336 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1852 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1048 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1196 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2344 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2500 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2496 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 788 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1776 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1576 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2360 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1368 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 620 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2116 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2036 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2148 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1184 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2768 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2640 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2756 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2652 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2532 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2008 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2204 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1672 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1868 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1664 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2804 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2368 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2108 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1488 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 828 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2336 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2076 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 752 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 620 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 852 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2036 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2104 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1184 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2768 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2648 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2756 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2680 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2532 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process target process PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2244 wrote to memory of 2824 2244 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2824 wrote to memory of 2092 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2824 wrote to memory of 2092 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2824 wrote to memory of 2092 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2824 wrote to memory of 2092 2824 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2092 wrote to memory of 2972 2092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2972 wrote to memory of 2644 2972 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2972 wrote to memory of 2644 2972 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2972 wrote to memory of 2644 2972 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2972 wrote to memory of 2644 2972 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2644 wrote to memory of 2772 2644 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2772 wrote to memory of 2524 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2772 wrote to memory of 2524 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2772 wrote to memory of 2524 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2772 wrote to memory of 2524 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2524 wrote to memory of 3032 2524 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3032 wrote to memory of 2296 3032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3032 wrote to memory of 2296 3032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3032 wrote to memory of 2296 3032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3032 wrote to memory of 2296 3032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 wrote to memory of 2604 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2604 wrote to memory of 2688 2604 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2604 wrote to memory of 2688 2604 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2604 wrote to memory of 2688 2604 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2604 wrote to memory of 2688 2604 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2688 wrote to memory of 2628 2688 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2628 wrote to memory of 2588 2628 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2628 wrote to memory of 2588 2628 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2628 wrote to memory of 2588 2628 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2628 wrote to memory of 2588 2628 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2588 wrote to memory of 2636 2588 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2588 wrote to memory of 2636 2588 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2588 wrote to memory of 2636 2588 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2588 wrote to memory of 2636 2588 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"1⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe2⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s3⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe4⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s5⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe6⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s7⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe8⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s9⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe10⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s11⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe12⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s13⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe14⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s15⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe16⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s17⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe18⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s19⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe20⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s21⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe22⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s23⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe24⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s25⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe26⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s27⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe28⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s29⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe30⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s31⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe32⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s33⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe34⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s35⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe36⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s37⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe38⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s39⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe40⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s41⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe42⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s43⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe44⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s45⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe46⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s47⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe48⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s49⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe50⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s51⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe52⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s53⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe54⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s55⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe56⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s57⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe58⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s59⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe60⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s61⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe62⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s63⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe64⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s65⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe66⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s67⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe68⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s69⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe70⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s71⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe72⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s73⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe74⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s75⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe76⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s77⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe78⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s79⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe80⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s81⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe82⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s83⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe84⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s85⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe86⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s87⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe88⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s89⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe90⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s91⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe92⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s93⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe94⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s95⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe96⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s97⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe98⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s99⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe100⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s101⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe102⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s103⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe104⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s105⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe106⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s107⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe108⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s109⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe110⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s111⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe112⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s113⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe114⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s115⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe116⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s117⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe118⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s119⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe120⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s121⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe122⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s123⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe124⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s125⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe126⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s127⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe128⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s129⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe130⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s131⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe132⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s133⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe134⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s135⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe136⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s137⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe138⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s139⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe140⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s141⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe142⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s143⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe144⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s145⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe146⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s147⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe148⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s149⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe150⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s151⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe152⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s153⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe154⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s155⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe156⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s157⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe158⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s159⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe160⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s161⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe162⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s163⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe164⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s165⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe166⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s167⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe168⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s169⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe170⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s171⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe172⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s173⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe174⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s175⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe176⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s177⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe178⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s179⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe180⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s181⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe182⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s183⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe184⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s185⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe186⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s187⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe188⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s189⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe190⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s191⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe192⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s193⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe194⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s195⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe196⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s197⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe198⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s199⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe200⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s201⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe202⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s203⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe204⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s205⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe206⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s207⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe208⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s209⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe210⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s211⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe212⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s213⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe214⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s215⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe216⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s217⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe218⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s219⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe220⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s221⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe222⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s223⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe224⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s225⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe226⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s227⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe228⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s229⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe230⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s231⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe232⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s233⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe234⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s235⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe236⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s237⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe238⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s239⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe240⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s241⤵