Technical Information
- gtkxmdvt.exe process, win32u.dll module
- gtkxmdvt.exe process, ntdll.dll module
- %TEMP%\myst-launcher-amd64.exe
- %HOMEPATH%\.mysterium-bin\myst.exe
- %HOMEPATH%\.mysterium-bin\myst.reg
- %HOMEPATH%\.mysterium-bin\myst_supervisor.exe
- %HOMEPATH%\.mysterium-node\config-mainnet.toml
- %HOMEPATH%\.mysterium-node\nodeui-pass
- %HOMEPATH%\.myst_node_launcher
- %HOMEPATH%\.mysterium-docs\aws.exe
- %HOMEPATH%\.mysterium-docs\awscli\botocore\.changes\next-release\api-change-connect-59117.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\cacert.pem
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\endpoints.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\partitions.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\paginators-1.sdk-extras.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\configure\_main.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\dynamodb\new-table.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\events\new-rule.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\iam\new-role.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\lambda\new-function.yml
- %HOMEPATH%\.mysterium-docs\awscli\data\cli.json
- %HOMEPATH%\.mysterium-docs\awscli\data\codedeploy\2014-10-06\completions-1.json
- %HOMEPATH%\.mysterium-docs\awscli\data\config\2014-11-12\completions-1.json
- %HOMEPATH%\.mysterium-docs\awscli\data\metadata.json
- %HOMEPATH%\.mysterium-docs\awscli\topics\config-vars.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\ddb-expressions.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\return-codes.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\s3-config.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\s3-faq.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\topic-tags.json
- %HOMEPATH%\.mysterium-docs\base_library.zip
- %HOMEPATH%\.mysterium-docs\cryptography\hazmat\bindings\_rust.pyd
- %HOMEPATH%\.mysterium-docs\libcrypto-3.dll
- %HOMEPATH%\.mysterium-docs\libffi-8.dll
- %HOMEPATH%\.mysterium-docs\libssl-3.dll
- %HOMEPATH%\.mysterium-docs\pyexpat.pyd
- %HOMEPATH%\.mysterium-docs\python3.dll
- %HOMEPATH%\.mysterium-docs\python311.dll
- %HOMEPATH%\.mysterium-docs\select.pyd
- %HOMEPATH%\.mysterium-docs\sqlite3.dll
- %HOMEPATH%\.mysterium-docs\unicodedata.pyd
- %HOMEPATH%\.mysterium-docs\vcruntime140.dll
- %HOMEPATH%\.mysterium-docs\_asyncio.pyd
- %HOMEPATH%\.mysterium-docs\_awscrt.pyd
- %HOMEPATH%\.mysterium-docs\_bz2.pyd
- %HOMEPATH%\.mysterium-docs\_cffi_backend.cp311-win_amd64.pyd
- %HOMEPATH%\.mysterium-docs\_ctypes.pyd
- %HOMEPATH%\.mysterium-docs\_decimal.pyd
- %HOMEPATH%\.mysterium-docs\_elementtree.pyd
- %HOMEPATH%\.mysterium-docs\_hashlib.pyd
- %HOMEPATH%\.mysterium-docs\_lzma.pyd
- %HOMEPATH%\.mysterium-docs\_multiprocessing.pyd
- %HOMEPATH%\.mysterium-docs\_overlapped.pyd
- %HOMEPATH%\.mysterium-docs\_queue.pyd
- %HOMEPATH%\.mysterium-docs\_ruamel_yaml.cp311-win_amd64.pyd
- %HOMEPATH%\.mysterium-docs\_socket.pyd
- %HOMEPATH%\.mysterium-docs\_sqlite3.pyd
- %HOMEPATH%\.mysterium-docs\_ssl.pyd
- %HOMEPATH%\.mysterium-docs\_uuid.pyd
- %TEMP%\840x24l6.bat
- nul
- %TEMP%\myst-launcher-amd64.exe
- %HOMEPATH%\.mysterium-bin\myst.exe
- %HOMEPATH%\.mysterium-bin\myst.reg
- %HOMEPATH%\.mysterium-bin\myst_supervisor.exe
- %HOMEPATH%\.mysterium-node\config-mainnet.toml
- %HOMEPATH%\.mysterium-node\nodeui-pass
- %HOMEPATH%\.myst_node_launcher
- %HOMEPATH%\.mysterium-docs\aws.exe
- %HOMEPATH%\.mysterium-docs\awscli\botocore\.changes\next-release\api-change-connect-59117.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\cacert.pem
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\config\2014-11-12\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\endpoints.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\partitions.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\paginators-1.sdk-extras.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3\2006-03-01\waiters-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3control\2018-08-20\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\endpoint-rule-set-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\paginators-1.json
- %HOMEPATH%\.mysterium-docs\awscli\botocore\data\s3outposts\2017-07-25\service-2.json
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\configure\_main.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\dynamodb\new-table.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\events\new-rule.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\iam\new-role.yml
- %HOMEPATH%\.mysterium-docs\awscli\customizations\wizard\wizards\lambda\new-function.yml
- %HOMEPATH%\.mysterium-docs\awscli\data\cli.json
- %HOMEPATH%\.mysterium-docs\awscli\data\codedeploy\2014-10-06\completions-1.json
- %HOMEPATH%\.mysterium-docs\awscli\data\config\2014-11-12\completions-1.json
- %HOMEPATH%\.mysterium-docs\awscli\data\metadata.json
- %HOMEPATH%\.mysterium-docs\awscli\topics\config-vars.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\ddb-expressions.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\return-codes.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\s3-config.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\s3-faq.rst
- %HOMEPATH%\.mysterium-docs\awscli\topics\topic-tags.json
- %HOMEPATH%\.mysterium-docs\base_library.zip
- %HOMEPATH%\.mysterium-docs\cryptography\hazmat\bindings\_rust.pyd
- %HOMEPATH%\.mysterium-docs\libcrypto-3.dll
- %HOMEPATH%\.mysterium-docs\libffi-8.dll
- %HOMEPATH%\.mysterium-docs\libssl-3.dll
- %HOMEPATH%\.mysterium-docs\pyexpat.pyd
- %HOMEPATH%\.mysterium-docs\python3.dll
- %HOMEPATH%\.mysterium-docs\python311.dll
- %HOMEPATH%\.mysterium-docs\select.pyd
- %HOMEPATH%\.mysterium-docs\sqlite3.dll
- %HOMEPATH%\.mysterium-docs\unicodedata.pyd
- %HOMEPATH%\.mysterium-docs\vcruntime140.dll
- %HOMEPATH%\.mysterium-docs\_asyncio.pyd
- %HOMEPATH%\.mysterium-docs\_awscrt.pyd
- %HOMEPATH%\.mysterium-docs\_bz2.pyd
- %HOMEPATH%\.mysterium-docs\_cffi_backend.cp311-win_amd64.pyd
- %HOMEPATH%\.mysterium-docs\_ctypes.pyd
- %HOMEPATH%\.mysterium-docs\_decimal.pyd
- %HOMEPATH%\.mysterium-docs\_elementtree.pyd
- %HOMEPATH%\.mysterium-docs\_hashlib.pyd
- %HOMEPATH%\.mysterium-docs\_lzma.pyd
- %HOMEPATH%\.mysterium-docs\_multiprocessing.pyd
- %HOMEPATH%\.mysterium-docs\_overlapped.pyd
- %HOMEPATH%\.mysterium-docs\_queue.pyd
- %HOMEPATH%\.mysterium-docs\_ruamel_yaml.cp311-win_amd64.pyd
- %HOMEPATH%\.mysterium-docs\_socket.pyd
- %HOMEPATH%\.mysterium-docs\_sqlite3.pyd
- %HOMEPATH%\.mysterium-docs\_ssl.pyd
- %HOMEPATH%\.mysterium-docs\_uuid.pyd
- DNS ASK ap#.#ithub.com
- '%TEMP%\myst-launcher-amd64.exe' -autorun
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\840X24L6.bat" "<Full path to file>" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer\Products" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer\Products\D3890429B8E023640887BDDDA19CEF6D" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer\Products\D3890429B8E023640887BDDDA19CEF6D\SourceList" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer\Products\D3890429B8E023640887BDDDA19CEF6D\SourceList\Media" /f
- '<SYSTEM32>\reg.exe' add "HKCU\SOFTWARE\Microsoft\Installer\Products\D3890429B8E023640887BDDDA19CEF6D\SourceList\Net" /f
- '<SYSTEM32>\reg.exe' import "%HOMEPATH%\.mysterium-bin\myst.reg"
- '<SYSTEM32>\timeout.exe' /t 3
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\findstr.exe' /i "myst-launcher-amd64.exe"
- '<SYSTEM32>\findstr.exe' /i "myst.exe"
- '<SYSTEM32>\timeout.exe' /t 10
- '<SYSTEM32>\timeout.exe' /t 300
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\840X24L6.bat" "<Full path to file>" "' (with hidden window)