Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /im "setup.exe" /f
- <SYSTEM32>\svchost.exe
- %TEMP%\nsb9c7e.tmp
- %TEMP%\is-re98q.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-re98q.tmp\idp.dll
- %TEMP%\rarsfx0\kiffapp2.exe
- %TEMP%\rarsfx0\sfx_123_400.exe
- %TEMP%\is-re98q.tmp\zab2our.exe
- %TEMP%\sqlite.dat
- %TEMP%\sqlite.dll
- %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\t2lmw1ma.newcfg
- %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\z5qxn3k2.newcfg
- %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\n0a2fiim.newcfg
- %TEMP%\chrome 5.exe
- %TEMP%\ixp000.tmp\benvenuta.xlsx
- %APPDATA%\4117927.exe
- %APPDATA%\6909120.exe
- %APPDATA%\3906601.exe
- %TEMP%\tmp5698_tmp.exe
- %APPDATA%\2861612.exe
- %APPDATA%\microsoft\windows\start menu\plswneu2.exe
- %TEMP%\publicdwlbrowser1100.exe
- %TEMP%\2.exe
- %TEMP%\ixp000.tmp\vedi.xlsx
- %TEMP%\ixp000.tmp\orrore.xlsx
- %TEMP%\is-re98q.tmp\_isetup\_setup64.tmp
- %TEMP%\lzmwaqmv.exe
- %TEMP%\is-k4i63.tmp\wed2276f461788d71.tmp
- %TEMP%\7zs83ae5b9f\libcurlpp.dll
- %TEMP%\setup.exe
- %TEMP%\7zs45ac45af\libgcc_s_dw2-1.dll
- %TEMP%\7zs45ac45af\libstdc++-6.dll
- %TEMP%\7zs45ac45af\libwinpthread-1.dll
- %TEMP%\7zs45ac45af\libzip.dll
- %TEMP%\7zs45ac45af\setup_install.exe
- %TEMP%\7zs45ac45af\zlib1.dll
- %TEMP%\7zs45ac45af\7227066b2a30.zip
- %TEMP%\2d40b7f8edeb326e.exe
- %TEMP%\7zs83ae5b9f\libcurl.dll
- %TEMP%\7zs83ae5b9f\libgcc_s_dw2-1.dll
- %TEMP%\7zs83ae5b9f\wed22ba1658550.exe
- %TEMP%\7zs83ae5b9f\libstdc++-6.dll
- %TEMP%\7zs83ae5b9f\libwinpthread-1.dll
- %TEMP%\7zs83ae5b9f\setup_install.exe
- %TEMP%\7zs83ae5b9f\wed220a78e02f9cdc2.exe
- %TEMP%\7zs83ae5b9f\wed220ea31c8d2529.exe
- %TEMP%\7zs83ae5b9f\wed2235d696e09087db.exe
- %TEMP%\7zs83ae5b9f\wed2259ec17c7e3de63.exe
- %TEMP%\7zs83ae5b9f\wed226a1ef36724b3ee.exe
- %TEMP%\7zs83ae5b9f\wed2276a59f98c5.exe
- %TEMP%\7zs83ae5b9f\wed2276f461788d71.exe
- %TEMP%\7zs83ae5b9f\wed22e50546816d16.exe
- %TEMP%\ixp000.tmp\corpo.xlsx
- %TEMP%\7zs45ac45af\7227066b2a30.zip
- %TEMP%\7zs45ac45af\libgcc_s_dw2-1.dll
- %TEMP%\7zs45ac45af\libstdc++-6.dll
- %TEMP%\7zs45ac45af\libwinpthread-1.dll
- %TEMP%\7zs45ac45af\libzip.dll
- %TEMP%\7zs45ac45af\setup_install.exe
- %TEMP%\7zs45ac45af\zlib1.dll
- %TEMP%\7zs83ae5b9f\libcurl.dll
- %TEMP%\7zs83ae5b9f\libcurlpp.dll
- %TEMP%\7zs83ae5b9f\libgcc_s_dw2-1.dll
- %TEMP%\7zs83ae5b9f\libstdc++-6.dll
- %TEMP%\7zs83ae5b9f\libwinpthread-1.dll
- %TEMP%\7zs83ae5b9f\setup_install.exe
- %TEMP%\7zs83ae5b9f\wed220a78e02f9cdc2.exe
- %TEMP%\sqlite.dat
- %TEMP%\setup.exe
- from %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\t2lmw1ma.newcfg to %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\user.config
- from %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\z5qxn3k2.newcfg to %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\user.config
- from %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\n0a2fiim.newcfg to %LOCALAPPDATA%\module_art\wed226a1ef36724b3ee.exe_url_vum5iey3ybvkw0gzdmroo0uorx52dido\1.2.1.0\user.config
- 'localhost':49174
- 'ki##.tech':443
- 'ac####tyhike.com':443
- 'ac####tyhike.com':80
- 'de###her.xyz':443
- 'ga###etwork.bar':443
- 'co###ctini.net':443
- '18#.#15.113.15':6043
- '2n#.co':443
- 'cd#.##scordapp.com':443
- '37.#.10.237':80
- '37.#.10.214':80
- 'a.###tgame.co':443
- 'sa###links.com':80
- 'le####49.tumblr.com':443
- 'hs##ns.xyz':80
- 'localhost':49176
- 'cd#.##scordapp.com':80
- 'oc##.#ectigo.com':80
- http://hs##ns.xyz/addInstall.php?ke##############################################################################################################################################################...
- http://sa###links.com/Installer_Provider/UltraMediaBurner.exe
- http://37.#.10.214/proxies.txt
- http://37.#.10.237/base/api/statistics.php
- http://ac####tyhike.com/files/jane30.exe
- http://oc##.#ectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEQDrMNf9g78s2B0RdM6vHPcU
- 'localhost':49174
- 'localhost':49176
- 'localhost':49177
- 'le####49.tumblr.com':443
- 'a.###tgame.co':443
- 'cd#.##scordapp.com':80
- 'cd#.##scordapp.com':443
- '18#.#15.113.15':6043
- 'co###ctini.net':443
- 'ga###etwork.bar':443
- 'de###her.xyz':443
- 'ac####tyhike.com':443
- '2n#.co':443
- DNS ASK hs##ns.xyz
- DNS ASK ki##.tech
- DNS ASK
- DNS ASK ac####tyhike.com
- DNS ASK de###her.xyz
- DNS ASK ga###etwork.bar
- DNS ASK re####network.xyz
- DNS ASK th######esportsgroup.net
- DNS ASK co###ctini.net
- DNS ASK
- DNS ASK go####.vrthcobj.com
- DNS ASK cd#.##scordapp.com
- DNS ASK sa###links.com
- DNS ASK a.###tgame.co
- DNS ASK le####49.tumblr.com
- DNS ASK 2n#.co
- DNS ASK oc##.#ectigo.com
- 'go####.vrthcobj.com':53
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\setup.exe'
- '%APPDATA%\3906601.exe'
- '%TEMP%\is-re98q.tmp\zab2our.exe' /S /UID=burnerch2
- '%APPDATA%\4117927.exe'
- '%TEMP%\chrome 5.exe'
- '%APPDATA%\6909120.exe'
- '%TEMP%\publicdwlbrowser1100.exe'
- '%APPDATA%\2861612.exe'
- '%APPDATA%\microsoft\windows\start menu\plswneu2.exe'
- '%TEMP%\is-k4i63.tmp\wed2276f461788d71.tmp' /SL5="$D0216,506086,422400,%TEMP%\7zS83AE5B9F\Wed2276f461788d71.exe"
- '%TEMP%\2.exe'
- '%TEMP%\rarsfx0\kiffapp2.exe'
- '%TEMP%\7zs83ae5b9f\wed2276f461788d71.exe'
- '%TEMP%\tmp5698_tmp.exe'
- '%TEMP%\7zs83ae5b9f\wed22e50546816d16.exe'
- '%TEMP%\7zs83ae5b9f\setup_install.exe'
- '%TEMP%\lzmwaqmv.exe'
- '%TEMP%\2d40b7f8edeb326e.exe'
- '%TEMP%\7zs83ae5b9f\wed226a1ef36724b3ee.exe'
- '%TEMP%\7zs83ae5b9f\wed2259ec17c7e3de63.exe'
- '%TEMP%\7zs83ae5b9f\wed220a78e02f9cdc2.exe'
- '%TEMP%\7zs45ac45af\setup_install.exe'
- '%TEMP%\7zs83ae5b9f\wed22ba1658550.exe'
- '%TEMP%\7zs83ae5b9f\wed220ea31c8d2529.exe'
- '%TEMP%\7zs83ae5b9f\wed2276a59f98c5.exe'
- '%TEMP%\7zs83ae5b9f\wed2235d696e09087db.exe'
- '%TEMP%\is-re98q.tmp\zab2our.exe' /S /UID=burnerch2' (with hidden window)
- '%APPDATA%\2861612.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Corpo.xlsx' (with hidden window)
- '%WINDIR%\syswow64\werfault.exe' -u -p 2760 -s 1596' (with hidden window)
- '%WINDIR%\syswow64\dllhost.exe' ' (with hidden window)
- '%APPDATA%\3906601.exe' ' (with hidden window)
- '%APPDATA%\6909120.exe' ' (with hidden window)
- '%APPDATA%\4117927.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "setup.exe" /f & erase "%TEMP%\setup.exe" & exit' (with hidden window)
- '%APPDATA%\1356868.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\2d40b7f8edeb326e.exe
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "setup.exe" /f & erase "%TEMP%\setup.exe" & exit
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Corpo.xlsx
- '%WINDIR%\syswow64\dllhost.exe'
- '<SYSTEM32>\svchost.exe' -k SystemNetworkService
- '<SYSTEM32>\rundll32.exe' "%TEMP%\sqlite.dll",global
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '%WINDIR%\syswow64\cmd.exe' /c Wed2259ec17c7e3de63.exe
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' /c Wed22e50546816d16.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed220ea31c8d2529.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed2276f461788d71.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed22ba1658550.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed2235d696e09087db.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed226a1ef36724b3ee.exe
- '%WINDIR%\syswow64\cmd.exe' /c Wed220a78e02f9cdc2.exe
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '%WINDIR%\syswow64\cmd.exe' /c Wed2276a59f98c5.exe
- '%WINDIR%\syswow64\findstr.exe' /V /R "^OthMvGQXeAyqUhASvlyrPDCQZpoKXyPgrCBJMOmLquNCguqHiGGcDIHkBbMhbyZWLRXsMRyHLzrIPZCToACsmzKxUdofejgUuRRvoIVdBYJlFZ$" Vedi.xlsx