Technical Information
- %TEMP%\_mei23762\vcruntime140.dll
- %TEMP%\_mei23762\_bz2.pyd
- %TEMP%\_mei23762\_decimal.pyd
- %TEMP%\_mei23762\_hashlib.pyd
- %TEMP%\_mei23762\_lzma.pyd
- %TEMP%\_mei23762\_socket.pyd
- %TEMP%\_mei23762\base_library.zip
- %TEMP%\_mei23762\libcrypto-3.dll
- %TEMP%\_mei23762\python311.dll
- %TEMP%\_mei23762\select.pyd
- %TEMP%\_mei23762\unicodedata.pyd
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-1040.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-aa4.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-6b4.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-aec.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cab-5bc.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cac-10fc.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cae-1718.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6caf-d24.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cbb-1484.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc2-514.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-48c.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-1160.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-bd8.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc4-eec.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc8-14dc.pma
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000002
- %LOCALAPPDATA%\microsoft\edge\user data\default\000002.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\reporting and nel-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\reporting and nel
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\000001.dbtmp
- %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\fadf0ed89fd24b21_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\c61ee740100c5bc7_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\4388a3184e36d470_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000002
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\c993321062af1cc1_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\6c612819f512bd62_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000003
- %LOCALAPPDATA%\microsoft\edge\user data\functional data-wal
- %LOCALAPPDATA%\microsoft\edge\user data\functional san data-wal
- %LOCALAPPDATA%\microsoft\edge\user data\default\manifest-000001
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-1040.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-6b4.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-aa4.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6ca8-aec.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cab-5bc.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cac-10fc.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cae-1718.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6caf-d24.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cbb-1484.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc2-514.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-1160.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-48c.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc3-bd8.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc4-eec.pma
- %LOCALAPPDATA%\microsoft\edge\user data\browsermetrics\browsermetrics-69fe6cc8-14dc.pma
- from %LOCALAPPDATA%\microsoft\edge\user data\default\000001.dbtmp to %LOCALAPPDATA%\microsoft\edge\user data\default\current
- from %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\000001.dbtmp to %LOCALAPPDATA%\microsoft\edge\user data\default\session storage\current
- from %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\000001.dbtmp to %LOCALAPPDATA%\microsoft\edge\user data\default\shared_proto_db\metadata\current
- from %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\000001.dbtmp to %LOCALAPPDATA%\microsoft\edge\user data\default\extension state\current
- %LOCALAPPDATA%\microsoft\edge\user data\last version
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\site characteristics database\log
- %LOCALAPPDATA%\microsoft\edge\user data\default\sync data\leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\tokenbroker\cache\9cd93bc6dcf544bae69531052e64647ec02f2bb4.tbres
- %LOCALAPPDATA%\microsoft\edge\user data\default\visited links
- %LOCALAPPDATA%\microsoft\edge\user data\default\history-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\local storage\leveldb\000003.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\history
- %TEMP%\.ses
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Local Storage\leveldb\LOG
- %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Platform Notifications\LOG
- 'co####.edge.skype.com':443
- 'rt.##rnhub.org':443
- 'xv##eos.com':443
- 'ha##me.tv':443
- 'xx#.com':443
- 'x1.#.lencr.org':80
- 'ei.##ncdn.com':443
- 'st####.trafficjunky.com':443
- 'pi#####77.phncdn.com':443
- 'pi####.phncdn.com':443
- 'pi####.trafficjunky.net':443
- http://x1.#.lencr.org/
- 'co####.edge.skype.com':443
- 'ha##me.tv':443
- 'rt.##rnhub.org':443
- 'xv##eos.com':443
- 'xx#.com':443
- 'ei.##ncdn.com':443
- 'st####.trafficjunky.com':443
- 'pi#####77.phncdn.com':443
- 'pi####.phncdn.com':443
- DNS ASK co####.edge.skype.com
- DNS ASK ha##me.tv
- DNS ASK xv##eos.com
- DNS ASK po##hub.com
- DNS ASK xx#.com
- DNS ASK rt.##rnhub.org
- DNS ASK x1.#.lencr.org
- DNS ASK ei.##ncdn.com
- DNS ASK st####.trafficjunky.com
- DNS ASK pi#####77.phncdn.com
- DNS ASK pi######7.trafficjunky.net
- DNS ASK pi####.trafficjunky.net
- DNS ASK pi####.phncdn.com
- ClassName: 'Chrome_MessageWindow' WindowName: '%LOCALAPPDATA%\Microsoft\Edge\User Data'
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --single-argument https://www.pornhub.com/
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --single-argument https://www.xvideos.com/
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --single-argument https://www.xxx.com/
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --single-argument https://hanime.tv/search
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --flag-switches-begin --flag-switches-end --do-not-de-elevate https://hanime.tv/search
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.pornhub.com/
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --flag-switches-begin --flag-switches-end --do-not-de-elevate https://hanime.tv/search' (with hidden window)
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --flag-switches-begin --flag-switches-end --do-not-de-elevate https://www.pornhub.com/' (with hidden window)