| 2019-02-20 18:07:01 | https://102.165.32.158:443/dash/ttm.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:54 | https://102.165.32.158:443/dash/sh.exe | Offline | exe Formbook hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:47 | https://102.165.32.158:443/dash/sehdyi.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:41 | https://102.165.32.158:443/dash/rbin.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:28 | https://102.165.32.158:443/dash/rbiin.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:22 | https://102.165.32.158:443/dash/doc.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:12 | https://102.165.32.158:443/dash/694818.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:06:03 | http://102.165.32.158:80/dash/ttm.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:54 | http://102.165.32.158:80/dash/sh.exe | Offline | exe Formbook hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:35 | http://102.165.32.158:80/dash/sehdyi.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:29 | http://102.165.32.158:80/dash/rbin.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:16 | http://102.165.32.158:80/dash/rbiin.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:10 | http://102.165.32.158:80/dash/694818.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:05:05 | http://102.165.32.158:80/dash/doc.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:49 | https://102.165.32.158/dash/ttm.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:41 | https://102.165.32.158/dash/sh.exe | Offline | exe Formbook hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:31 | https://102.165.32.158/dash/sehdyi.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:24 | https://102.165.32.158/dash/rbin.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:16 | https://102.165.32.158/dash/rbiin.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:10 | https://102.165.32.158/dash/doc.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:04:01 | https://102.165.32.158/dash/694818.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:03:31 | http://102.165.32.158/dash/ttm.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:03:22 | http://102.165.32.158/dash/sh.exe | Offline | exe Formbook hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:03:07 | http://102.165.32.158/dash/sehdyi.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:02:58 | http://102.165.32.158/dash/rbin.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:02:41 | http://102.165.32.158/dash/rbiin.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:02:34 | http://102.165.32.158/dash/694818.hta | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |
| 2019-02-20 18:02:16 | http://102.165.32.158/dash/doc.exe | Offline | exe hta Loader payload stage2 stage3 | shotgunner101 |