Session
demo-critical-exfil
No notes yet. Leave the first one so the next reviewer inherits the context.
Timeline · 12 events
- 2026-04-22
-
20:14
-
20:14:21process_start Process startedC:\Users\bill\AppData\Roaming\Claude\claude-code\2.1.111\claude.exepid 9900 -
20:14:23process_start Process startedC:\Windows\System32\cmd.exepid 9100 -
20:14:25file_open OpenedC:\Users\ci\.aws\credentialspid 9900 sensitive -
20:14:26file_open OpenedC:\Users\ci\.ssh\id_rsapid 9900 sensitive -
20:14:27dns DNS lookuppastebin.compid 9900 -
20:14:29file_write WroteC:\Users\ci\AppData\Local\Temp\svc-updater.exepid 9900 -
20:14:31image_load Loaded imageC:\Users\ci\AppData\Local\Temp\svc-updater.exe · session-writtenpid 9100 -
20:14:33registry_set Wrote registry\REGISTRY\USER\S-1-5-21-1000\Software\Microsoft\Windows\CurrentVersion\Run\SvcUpdater · run keypid 9100 -
20:14:35udp_connect UDP send185.220.101.42:4444 (udp)pid 9100 -
20:14:36udp_connect UDP send45.137.21.9:53413 (udp)pid 9100 -
20:14:39process_start Process startedpowershell -EncodedCommand JABjACAAPQAgACIASABlAGwAbABvACIAOwAgACQAYwA=pid 9101 -
20:14:41process_start Process startedsc.exe create SvcUpdater binPath= "C:\Users\ci\AppData\Local\Temp\svc-updater.exe" start= autopid 9102
-