Analysis
-
max time kernel
149s -
max time network
151s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 07:51
Behavioral task
behavioral1
Sample
1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll
Resource
win10v2004-20240508-en
General
-
Target
1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll
-
Size
6KB
-
MD5
1a7fea1b250d9ff99b0281dd5316568c
-
SHA1
b7750359e505f0a405babf9a83c8978d559b319a
-
SHA256
9579f183cee828f21d7fcb048d68815a248df081f602143be05db6e68f4ba27f
-
SHA512
af2df900090b04954a2987838db98f0c773e6381646fa13e16b4ea49c51398322402c216215425a45dd51f2d6f670fdec593209c26b4cee74fa2b5bf30cbc707
-
SSDEEP
96:63CjcnHqT5noRDei0x16WES01x9jF7COMjr78ERGvBsmi:66cnu5njBxEWo9p7U/78tBsmi
Malware Config
Signatures
-
Checks SCSI registry key(s) 3 TTPs 6 IoCs
SCSI information is often read in order to detect sandboxing environments.
Processes:
dwm.exedescription ioc process Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\CDROM&VEN_QEMU&PROD_QEMU_DVD-ROM\4&215468A5&0&010000 dwm.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\CdRom&Ven_QEMU&Prod_QEMU_DVD-ROM\4&215468a5&0&010000\ConfigFlags dwm.exe Key opened \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\DISK&VEN_DADY&PROD_HARDDISK\4&215468A5&0&000000 dwm.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\ConfigFlags dwm.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\CdRom&Ven_QEMU&Prod_QEMU_DVD-ROM\4&215468a5&0&010000\HardwareID dwm.exe Key value queried \REGISTRY\MACHINE\SYSTEM\ControlSet001\Enum\SCSI\Disk&Ven_DADY&Prod_HARDDISK\4&215468a5&0&000000\HardwareID dwm.exe -
Enumerates system info in registry 2 TTPs 2 IoCs
Processes:
dwm.exedescription ioc process Key opened \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS dwm.exe Key value queried \REGISTRY\MACHINE\HARDWARE\DESCRIPTION\System\BIOS\SystemSKU dwm.exe -
Modifies data under HKEY_USERS 18 IoCs
Processes:
dwm.exedescription ioc process Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\Disallowed dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\TrustedPeople dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\TrustedPeople dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\CA dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Disallowed dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\Root dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Microsoft\SystemCertificates\trust dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\trust dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Classes\Local Settings\MuiCache dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft\SystemCertificates\CA dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Classes\Local Settings\MuiCache\2a\52C64B7E dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies dwm.exe Key created \REGISTRY\USER\.DEFAULT\Software\Policies\Microsoft dwm.exe -
Suspicious use of AdjustPrivilegeToken 4 IoCs
Processes:
dwm.exedescription pid process Token: SeCreateGlobalPrivilege 17184 dwm.exe Token: SeChangeNotifyPrivilege 17184 dwm.exe Token: 33 17184 dwm.exe Token: SeIncBasePriorityPrivilege 17184 dwm.exe -
Suspicious use of WriteProcessMemory 64 IoCs
Processes:
rundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exerundll32.exedescription pid process target process PID 764 wrote to memory of 5092 764 rundll32.exe rundll32.exe PID 764 wrote to memory of 5092 764 rundll32.exe rundll32.exe PID 764 wrote to memory of 5092 764 rundll32.exe rundll32.exe PID 5092 wrote to memory of 4952 5092 rundll32.exe rundll32.exe PID 5092 wrote to memory of 4952 5092 rundll32.exe rundll32.exe PID 5092 wrote to memory of 4952 5092 rundll32.exe rundll32.exe PID 4952 wrote to memory of 5100 4952 rundll32.exe rundll32.exe PID 4952 wrote to memory of 5100 4952 rundll32.exe rundll32.exe PID 4952 wrote to memory of 5100 4952 rundll32.exe rundll32.exe PID 5100 wrote to memory of 4676 5100 rundll32.exe rundll32.exe PID 5100 wrote to memory of 4676 5100 rundll32.exe rundll32.exe PID 5100 wrote to memory of 4676 5100 rundll32.exe rundll32.exe PID 4676 wrote to memory of 2716 4676 rundll32.exe rundll32.exe PID 4676 wrote to memory of 2716 4676 rundll32.exe rundll32.exe PID 4676 wrote to memory of 2716 4676 rundll32.exe rundll32.exe PID 2716 wrote to memory of 4540 2716 rundll32.exe rundll32.exe PID 2716 wrote to memory of 4540 2716 rundll32.exe rundll32.exe PID 2716 wrote to memory of 4540 2716 rundll32.exe rundll32.exe PID 4540 wrote to memory of 3032 4540 rundll32.exe rundll32.exe PID 4540 wrote to memory of 3032 4540 rundll32.exe rundll32.exe PID 4540 wrote to memory of 3032 4540 rundll32.exe rundll32.exe PID 3032 wrote to memory of 3052 3032 rundll32.exe rundll32.exe PID 3032 wrote to memory of 3052 3032 rundll32.exe rundll32.exe PID 3032 wrote to memory of 3052 3032 rundll32.exe rundll32.exe PID 3052 wrote to memory of 2444 3052 rundll32.exe rundll32.exe PID 3052 wrote to memory of 2444 3052 rundll32.exe rundll32.exe PID 3052 wrote to memory of 2444 3052 rundll32.exe rundll32.exe PID 2444 wrote to memory of 4908 2444 rundll32.exe rundll32.exe PID 2444 wrote to memory of 4908 2444 rundll32.exe rundll32.exe PID 2444 wrote to memory of 4908 2444 rundll32.exe rundll32.exe PID 4908 wrote to memory of 4436 4908 rundll32.exe rundll32.exe PID 4908 wrote to memory of 4436 4908 rundll32.exe rundll32.exe PID 4908 wrote to memory of 4436 4908 rundll32.exe rundll32.exe PID 4436 wrote to memory of 2460 4436 rundll32.exe rundll32.exe PID 4436 wrote to memory of 2460 4436 rundll32.exe rundll32.exe PID 4436 wrote to memory of 2460 4436 rundll32.exe rundll32.exe PID 2460 wrote to memory of 692 2460 rundll32.exe rundll32.exe PID 2460 wrote to memory of 692 2460 rundll32.exe rundll32.exe PID 2460 wrote to memory of 692 2460 rundll32.exe rundll32.exe PID 692 wrote to memory of 4512 692 rundll32.exe rundll32.exe PID 692 wrote to memory of 4512 692 rundll32.exe rundll32.exe PID 692 wrote to memory of 4512 692 rundll32.exe rundll32.exe PID 4512 wrote to memory of 3852 4512 rundll32.exe rundll32.exe PID 4512 wrote to memory of 3852 4512 rundll32.exe rundll32.exe PID 4512 wrote to memory of 3852 4512 rundll32.exe rundll32.exe PID 3852 wrote to memory of 4680 3852 rundll32.exe rundll32.exe PID 3852 wrote to memory of 4680 3852 rundll32.exe rundll32.exe PID 3852 wrote to memory of 4680 3852 rundll32.exe rundll32.exe PID 4680 wrote to memory of 3940 4680 rundll32.exe rundll32.exe PID 4680 wrote to memory of 3940 4680 rundll32.exe rundll32.exe PID 4680 wrote to memory of 3940 4680 rundll32.exe rundll32.exe PID 3940 wrote to memory of 3840 3940 rundll32.exe rundll32.exe PID 3940 wrote to memory of 3840 3940 rundll32.exe rundll32.exe PID 3940 wrote to memory of 3840 3940 rundll32.exe rundll32.exe PID 3840 wrote to memory of 1740 3840 rundll32.exe rundll32.exe PID 3840 wrote to memory of 1740 3840 rundll32.exe rundll32.exe PID 3840 wrote to memory of 1740 3840 rundll32.exe rundll32.exe PID 1740 wrote to memory of 3904 1740 rundll32.exe rundll32.exe PID 1740 wrote to memory of 3904 1740 rundll32.exe rundll32.exe PID 1740 wrote to memory of 3904 1740 rundll32.exe rundll32.exe PID 3904 wrote to memory of 2848 3904 rundll32.exe rundll32.exe PID 3904 wrote to memory of 2848 3904 rundll32.exe rundll32.exe PID 3904 wrote to memory of 2848 3904 rundll32.exe rundll32.exe PID 2848 wrote to memory of 4344 2848 rundll32.exe rundll32.exe
Processes
-
C:\Windows\system32\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#11⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#12⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#13⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#14⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#15⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#16⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#17⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#18⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#19⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#110⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#111⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#112⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#113⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#114⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#115⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#116⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#117⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#118⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#119⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#120⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#121⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#122⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#123⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#124⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#125⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#126⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#127⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#128⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#129⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#130⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#131⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#132⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#133⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#134⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#135⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#136⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#137⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#138⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#139⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#140⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#141⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#142⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#143⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#144⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#145⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#146⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#147⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#148⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#149⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#150⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#151⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#152⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#153⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#154⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#155⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#156⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#157⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#158⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#159⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#160⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#161⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#162⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#163⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#164⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#165⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#166⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#167⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#168⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#169⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#170⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#171⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#172⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#173⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#174⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#175⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#176⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#177⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#178⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#179⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#180⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#181⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#182⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#183⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#184⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#185⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#186⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#187⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#188⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#189⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#190⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#191⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#192⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#193⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#194⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#195⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#196⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#197⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#198⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#199⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1100⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1101⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1102⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1103⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1104⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1105⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1106⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1107⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1108⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1109⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1110⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1111⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1112⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1113⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1114⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1115⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1116⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1117⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1118⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1119⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1120⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1121⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1122⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1123⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1124⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1125⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1126⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1127⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1128⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1129⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1130⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1131⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1132⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1133⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1134⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1135⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1136⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1137⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1138⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1139⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1140⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1141⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1142⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1143⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1144⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1145⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1146⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1147⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1148⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1149⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1150⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1151⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1152⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1153⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1154⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1155⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1156⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1157⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1158⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1159⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1160⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1161⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1162⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1163⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1164⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1165⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1166⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1167⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1168⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1169⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1170⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1171⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1172⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1173⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1174⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1175⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1176⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1177⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1178⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1179⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1180⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1181⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1182⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1183⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1184⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1185⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1186⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1187⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1188⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1189⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1190⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1191⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1192⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1193⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1194⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1195⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1196⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1197⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1198⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1199⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1200⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1201⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1202⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1203⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1204⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1205⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1206⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1207⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1208⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1209⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1210⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1211⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1212⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1213⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1214⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1215⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1216⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1217⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1218⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1219⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1220⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1221⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1222⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1223⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1224⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1225⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1226⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1227⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1228⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1229⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1230⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1231⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1232⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1233⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1234⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1235⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1236⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1237⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1238⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1239⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1240⤵
-
C:\Windows\SysWOW64\rundll32.exerundll32.exe C:\Users\Admin\AppData\Local\Temp\1a7fea1b250d9ff99b0281dd5316568c_JaffaCakes118.dll,#1241⤵