Analysis
-
max time kernel
149s -
max time network
124s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
28-06-2024 06:34
Behavioral task
behavioral1
Sample
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Resource
win10v2004-20240611-en
General
-
Target
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
-
Size
68KB
-
MD5
19224d8fe2957721118d14faef5096ce
-
SHA1
2438ee98bc8a07143c6e64c7a1bcb1386878baa3
-
SHA256
fb4aef1c345a246ca40f7629e3a760a69e7a84161995286cda1fd26aa74c3ae9
-
SHA512
867d2e0d94ab71c4d6eb2ec9df1c79ebbca8b6d3db8c0f58cf27bb1ea852c0caed39fe058f0ed194df41354177881ee2d8ae4d9c59b10c3afbcb17a3425833de
-
SSDEEP
1536:p4jqi5axwdaPpyNlDgS54QuZxDuKTVWCrx4LTT61B8:ujpaxGaPpyNV54DyiVd12
Malware Config
Signatures
-
ModiLoader, DBatLoader
ModiLoader is a Delphi loader that misuses cloud services to download other malicious families.
-
ModiLoader Second Stage 20 IoCs
Processes:
resource yara_rule behavioral2/memory/940-3-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4944-9-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/3028-15-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/1408-19-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4164-22-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/1012-25-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4216-28-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4176-31-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/2928-34-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/3312-37-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4500-40-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/640-43-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/3192-46-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/3048-49-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4964-52-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/2304-55-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/4108-58-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/1408-61-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/5048-64-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 behavioral2/memory/880-67-0x0000000010000000-0x0000000010017000-memory.dmp modiloader_stage2 -
Checks computer location settings 2 TTPs 64 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Key value queried \REGISTRY\USER\S-1-5-21-4204450073-1267028356-951339405-1000\Control Panel\International\Geo\Nation 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe -
Suspicious use of SetThreadContext 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process target process PID 940 set thread context of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 set thread context of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 set thread context of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 set thread context of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 set thread context of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 set thread context of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 set thread context of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 set thread context of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2928 set thread context of 4116 2928 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3312 set thread context of 1848 3312 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4500 set thread context of 4384 4500 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 640 set thread context of 396 640 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3192 set thread context of 4236 3192 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3048 set thread context of 2872 3048 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4964 set thread context of 3700 4964 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2304 set thread context of 2492 2304 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4108 set thread context of 4800 4108 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 set thread context of 3416 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5048 set thread context of 4768 5048 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 880 set thread context of 3660 880 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1744 set thread context of 2220 1744 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4472 set thread context of 4092 4472 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3980 set thread context of 4248 3980 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2928 set thread context of 1184 2928 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2912 set thread context of 2840 2912 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1940 set thread context of 1936 1940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4328 set thread context of 684 4328 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2296 set thread context of 2480 2296 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1384 set thread context of 2328 1384 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2736 set thread context of 1852 2736 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4480 set thread context of 4864 4480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1032 set thread context of 1812 1032 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2444 set thread context of 1768 2444 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4232 set thread context of 2744 4232 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3480 set thread context of 3132 3480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5088 set thread context of 1012 5088 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1788 set thread context of 4024 1788 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1544 set thread context of 412 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2900 set thread context of 3040 2900 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3980 set thread context of 4536 3980 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5104 set thread context of 1184 5104 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4324 set thread context of 984 4324 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3168 set thread context of 4540 3168 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4400 set thread context of 2004 4400 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3656 set thread context of 976 3656 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2872 set thread context of 4652 2872 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2492 set thread context of 1580 2492 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4152 set thread context of 1812 4152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1768 set thread context of 5000 1768 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2744 set thread context of 3448 2744 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5028 set thread context of 1272 5028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 888 set thread context of 372 888 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1096 set thread context of 1544 1096 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1864 set thread context of 2900 1864 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3744 set thread context of 2508 3744 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5052 set thread context of 3108 5052 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2544 set thread context of 2320 2544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 5044 set thread context of 4360 5044 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4500 set thread context of 3320 4500 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4932 set thread context of 4880 4932 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2772 set thread context of 4376 2772 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4996 set thread context of 1532 4996 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1852 set thread context of 3892 1852 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 2760 set thread context of 3204 2760 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious use of AdjustPrivilegeToken 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process Token: SeIncBasePriorityPrivilege 968 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3144 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4020 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1192 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3520 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4116 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1848 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4384 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 396 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4236 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2872 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3700 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2492 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4800 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3416 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4768 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3660 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2220 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4092 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1184 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2840 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1936 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 684 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2480 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2328 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1852 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4864 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1812 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1768 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2744 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3132 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4024 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 412 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3040 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4536 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1184 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 984 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4540 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2004 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 976 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4652 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1580 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1812 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 5000 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3448 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1272 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 372 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2900 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2508 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3108 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 2320 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4360 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3320 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4880 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 4376 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 1532 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3892 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe Token: SeIncBasePriorityPrivilege 3204 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe19224d8fe2957721118d14faef5096ce_JaffaCakes118.exedescription pid process target process PID 940 wrote to memory of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 940 wrote to memory of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 940 wrote to memory of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 940 wrote to memory of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 940 wrote to memory of 968 940 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 968 wrote to memory of 4944 968 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 968 wrote to memory of 4944 968 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 968 wrote to memory of 4944 968 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 wrote to memory of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 wrote to memory of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 wrote to memory of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 wrote to memory of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4944 wrote to memory of 3144 4944 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3144 wrote to memory of 3028 3144 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3144 wrote to memory of 3028 3144 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3144 wrote to memory of 3028 3144 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 wrote to memory of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 wrote to memory of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 wrote to memory of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 wrote to memory of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3028 wrote to memory of 4152 3028 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4152 wrote to memory of 1408 4152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4152 wrote to memory of 1408 4152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4152 wrote to memory of 1408 4152 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 wrote to memory of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 wrote to memory of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 wrote to memory of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 wrote to memory of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1408 wrote to memory of 4020 1408 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4020 wrote to memory of 4164 4020 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4020 wrote to memory of 4164 4020 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4020 wrote to memory of 4164 4020 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 wrote to memory of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 wrote to memory of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 wrote to memory of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 wrote to memory of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4164 wrote to memory of 1192 4164 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1192 wrote to memory of 1012 1192 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1192 wrote to memory of 1012 1192 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1192 wrote to memory of 1012 1192 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 wrote to memory of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 wrote to memory of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 wrote to memory of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 wrote to memory of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1012 wrote to memory of 1544 1012 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1544 wrote to memory of 4216 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1544 wrote to memory of 4216 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 1544 wrote to memory of 4216 1544 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 wrote to memory of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 wrote to memory of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 wrote to memory of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 wrote to memory of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4216 wrote to memory of 3520 4216 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3520 wrote to memory of 4176 3520 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3520 wrote to memory of 4176 3520 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3520 wrote to memory of 4176 3520 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 wrote to memory of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 wrote to memory of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 wrote to memory of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 wrote to memory of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 4176 wrote to memory of 3248 4176 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3248 wrote to memory of 2928 3248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3248 wrote to memory of 2928 3248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe PID 3248 wrote to memory of 2928 3248 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe 19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"1⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe2⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s3⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe4⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s5⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe6⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s7⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe8⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s9⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe10⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s11⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe12⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s13⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe14⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s15⤵
- Suspicious use of SetThreadContext
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe16⤵
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s17⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe18⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s19⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe20⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s21⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe22⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s23⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe24⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s25⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe26⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s27⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe28⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s29⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe30⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s31⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe32⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s33⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe34⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s35⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe36⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s37⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe38⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s39⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe40⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s41⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe42⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s43⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe44⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s45⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe46⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s47⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe48⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s49⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe50⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s51⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe52⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s53⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe54⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s55⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe56⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s57⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe58⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s59⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe60⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s61⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe62⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s63⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe64⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s65⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe66⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s67⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe68⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s69⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe70⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s71⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe72⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s73⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe74⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s75⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe76⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s77⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe78⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s79⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe80⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s81⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe82⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s83⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe84⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s85⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe86⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s87⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe88⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s89⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe90⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s91⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe92⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s93⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe94⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s95⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe96⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s97⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe98⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s99⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe100⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s101⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe102⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s103⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe104⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s105⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe106⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s107⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe108⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s109⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe110⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s111⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe112⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s113⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe114⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s115⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe116⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s117⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe118⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s119⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe120⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s121⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe122⤵
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s123⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe124⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s125⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe126⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s127⤵
- Suspicious use of SetThreadContext
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe128⤵
- Checks computer location settings
- Suspicious use of AdjustPrivilegeToken
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s129⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe130⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s131⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe132⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s133⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe134⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s135⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe136⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s137⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe138⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s139⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe140⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s141⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe142⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s143⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe144⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s145⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe146⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s147⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe148⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s149⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe150⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s151⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe152⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s153⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe154⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s155⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe156⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s157⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe158⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s159⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe160⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s161⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe162⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s163⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe164⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s165⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe166⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s167⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe168⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s169⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe170⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s171⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe172⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s173⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe174⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s175⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe176⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s177⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe178⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s179⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe180⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s181⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe182⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s183⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe184⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s185⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe186⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s187⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe188⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s189⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe190⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s191⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe192⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s193⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe194⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s195⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe196⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s197⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe198⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s199⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe200⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s201⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe202⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s203⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe204⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s205⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe206⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s207⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe208⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s209⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe210⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s211⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe212⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s213⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe214⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s215⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe216⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s217⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe218⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s219⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe220⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s221⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe222⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s223⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe224⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s225⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe226⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s227⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe228⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s229⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe230⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s231⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe232⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s233⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe234⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s235⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe236⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s237⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe238⤵
- Checks computer location settings
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s239⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exeC:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe240⤵
-
C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe"C:\Users\Admin\AppData\Local\Temp\19224d8fe2957721118d14faef5096ce_JaffaCakes118.exe" -s241⤵