4b14e2c7-b80e-8ccf-cd49-0600a4b1280304cb10a7-d1fe-4cc8-8aa4-deaf295a63d5 13 2 4 13 0 0x8000000000000000 5628 Microsoft-Windows-Sysmon/Operational EC2AMAZ-UGL8NO0 - SetValue 2026-03-18 15:45:26.411 2835B818-C87E-69BA-8805-000000004303 7244 c:\windows\SysWOW64\rundll32.exe HKU\S-1-5-21-1852115508-2520817528-1255656447-1008\Software\Microsoft\Windows\CurrentVersion\Run\EvtMgr c:\windows\SysWOW64\rundll32.exe "c:\qhccl\xmfav.max",RAFlush EC2AMAZ-UGL8NO0\user
4b14e2c7-b80e-8ccf-cd49-0600a4b12803f0dfb859-5121-44fb-83b1-fca56d51edc3 4688 2 0 13312 0 0x8020000000000000 185925 Security EC2AMAZ-UGL8NO0 S-1-5-21-1852115508-2520817528-1255656447-1008 user EC2AMAZ-UGL8NO0 0x38af7 0x1c4c C:\Windows\SysWOW64\rundll32.exe %%1938 0xef8 c:\windows\system32\rundll32.exe "c:\qhccl\xmfav.max",RAFlush C:\Users\user\AppData\Local\Temp\2\vequmgb.exe S-1-0-0 - - 0x0 C:\Users\user\AppData\Local\Temp\2\vequmgb.exe S-1-16-8192
4b14e2c7-b80e-8ccf-cd49-0600a4b12803fba0b200-fd7f-47f1-b406-1bb7635a10fa 1 5 4 1 0 0x8000000000000000 5558 Microsoft-Windows-Sysmon/Operational EC2AMAZ-UGL8NO0 - 2026-03-18 15:45:02.075 2835B818-C87E-69BA-8805-000000004303 7244 C:\Windows\SysWOW64\rundll32.exe 10.0.17763.1697 (WinBuild.160101.0800) Windows host process (Rundll32) Microsoft® Windows® Operating System Microsoft Corporation RUNDLL32.EXE c:\windows\system32\rundll32.exe "c:\qhccl\xmfav.max",RAFlush C:\Users\user\AppData\Local\Temp\2\vequmgb.exe C:\Users\user\Downloads\ EC2AMAZ-UGL8NO0\user 2835B818-C684-69BA-F78A-030000000000 0x38af7 2 Medium MD5=8459D693C951248A5E8E128F299E9618,SHA256=82611E60A2C5DE23A1B976BB3B9A32C4427CB60A002E4C27CADFA84031D87999,IMPHASH=BB17B2FBBFF4BBF5EBDCA7D0BB9E4A5B 2835B818-C87D-69BA-8705-000000004303 3832 C:\Users\user\AppData\Local\Temp\2\vequmgb.exe C:\Users\user\AppData\Local\Temp\2\\vequmgb.exe "C:\Users\user\Downloads\gh0strat_dump_SCY.exe" EC2AMAZ-UGL8NO0\user