Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- '' (downloaded from the Internet)
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\mozilla\firefox\profiles.ini
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\nsr82e6.tmp\sibuia.dll
- %TEMP%\v1fwhfgipbx\_files\_allforms_list.txt
- %TEMP%\v1fwhfgipbx\files_\forms.txt
- %TEMP%\v1fwhfgipbx\c5jmn.tmp-shm
- %TEMP%\v1fwhfgipbx\_files\_cookies\mozilla_firefox.txt
- %TEMP%\v1fwhfgipbx\files_\cookies\mozilla_firefox.txt
- %TEMP%\v1fwhfgipbx\_files\_screen_desktop.jpeg
- %TEMP%\v1fwhfgipbx\_files\_information.txt
- %TEMP%\v1fwhfgipbx\files_\screenshot.jpg
- %TEMP%\v1fwhfgipbx\files_\system_info.txt
- %TEMP%\v1fwhfgipbx\mug2juetsy.zip
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\sib83d1.tmp\2\lo2.exe
- %TEMP%\lsgusou.exe
- %TEMP%\tamxygxxoorn.exe
- %ALLUSERSPROFILE%\sib\{2b2be57f-3175-4770-aef4-26ab2e845cfc}\sib.dat
- %ALLUSERSPROFILE%\sib\{2b2be57f-3175-4770-aef4-26ab2e845cfc}\sibclr.dll
- %ALLUSERSPROFILE%\sib\{2b2be57f-3175-4770-aef4-26ab2e845cfc}\sibca.dll
- %ALLUSERSPROFILE%\xywnqikni\8372422.txt
- %ALLUSERSPROFILE%\xywnqikni\files\_information.txt
- %ALLUSERSPROFILE%\xywnqikni\46173476.txt
- %TEMP%\v1fwhfgipbx\fehs8.tmp
- %TEMP%\v1fwhfgipbx\se2rsgyouhkk.zip
- %TEMP%\v1fwhfgipbx\c5jmn.tmp
- %TEMP%\v1fwhfgipbx\5t2kb.tmp
- %TEMP%\sib83d1.tmp\sibca.dll
- %TEMP%\sib83d1.tmp\sibclr.dll
- %TEMP%\sib83d1.tmp\0\f17.vbs
- %TEMP%\sib83d1.tmp\1\drk2.exe
- %TEMP%\v1fwhfgipbx\zdiejv.tmp
- %TEMP%\v1fwhfgipbx\gjqrk.tmp
- %TEMP%\v1fwhfgipbx\6vng.tmp
- %TEMP%\v1fwhfgipbx\wl48tn.tmp
- %TEMP%\v1fwhfgipbx\qamduc.tmp
- %TEMP%\v1fwhfgipbx\gios.tmp
- %TEMP%\v1fwhfgipbx\_files\_cookies\opera.txt
- %TEMP%\v1fwhfgipbx\tryu.tmp
- %TEMP%\v1fwhfgipbx\tvbpwc.tmp
- %TEMP%\v1fwhfgipbx\_files\_cookies\google_chrome.txt
- %TEMP%\v1fwhfgipbx\files_\cookies\google_chrome.txt
- %TEMP%\v1fwhfgipbx\_files\_allcookies_list.txt
- %TEMP%\v1fwhfgipbx\files_\cookies.txt
- %TEMP%\v1fwhfgipbx\vmjjq.tmp
- %TEMP%\v1fwhfgipbx\vzbas6.tmp
- %TEMP%\v1fwhfgipbx\r1jax.tmp
- %TEMP%\v1fwhfgipbx\files_\cookies\opera.txt
- %ALLUSERSPROFILE%\xywnqikni\nl_2020_10_12___18_24___eqqon_95.211.190.199.zip
- %TEMP%\v1fwhfgipbx\c5jmn.tmp-shm
- %ALLUSERSPROFILE%\xywnqikni\46173476.txt
- %TEMP%\nsr82e6.tmp\sibuia.dll
- %TEMP%\sib83d1.tmp\sibclr.dll
- %TEMP%\sib83d1.tmp\sibca.dll
- %TEMP%\sib83d1.tmp\2\lo2.exe
- %TEMP%\sib83d1.tmp\0\f17.vbs
- %TEMP%\sib83d1.tmp\1\drk2.exe
- %TEMP%\v1fwhfgipbx\_files\_cookies\opera.txt
- %TEMP%\v1fwhfgipbx\zdiejv.tmp
- %TEMP%\v1fwhfgipbx\wl48tn.tmp
- %TEMP%\v1fwhfgipbx\vzbas6.tmp
- %TEMP%\v1fwhfgipbx\vmjjq.tmp
- %TEMP%\v1fwhfgipbx\tvbpwc.tmp
- %TEMP%\v1fwhfgipbx\tryu.tmp
- %TEMP%\v1fwhfgipbx\r1jax.tmp
- %TEMP%\v1fwhfgipbx\qamduc.tmp
- %TEMP%\v1fwhfgipbx\gjqrk.tmp
- %TEMP%\v1fwhfgipbx\gios.tmp
- %TEMP%\v1fwhfgipbx\files_\forms.txt
- %TEMP%\v1fwhfgipbx\files_\cookies.txt
- %TEMP%\v1fwhfgipbx\files_\cookies\opera.txt
- %TEMP%\v1fwhfgipbx\fehs8.tmp
- %TEMP%\v1fwhfgipbx\c5jmn.tmp
- %TEMP%\v1fwhfgipbx\6vng.tmp
- %TEMP%\v1fwhfgipbx\5t2kb.tmp
- %ALLUSERSPROFILE%\xywnqikni\8372422.txt
- %TEMP%\lsgusou.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- http://xe###load01.top/download.php?fi########
- http://xe###load01.top/downfiles/6.exe
- http://xe###load01.top/downfiles/4.exe
- http://ip##pi.com/line
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- http://nk###w04.top/index.php
- http://mo###ss07.top/index.php
- DNS ASK ip###ger.org
- DNS ASK microsoft.com
- DNS ASK nk###w04.top
- DNS ASK mo###ss07.top
- DNS ASK xe###load01.top
- DNS ASK ip##pi.com
- DNS ASK oc##.#tartssl.com
- ClassName: '18467-41' WindowName: ''
- '%TEMP%\sib83d1.tmp\1\drk2.exe' /s
- '%TEMP%\sib83d1.tmp\2\lo2.exe' /s
- '%TEMP%\lsgusou.exe'
- '%TEMP%\tamxygxxoorn.exe'
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\V1fWHfGiPBX & timeout 2 & del /f /q "%TEMP%\sib83D1.tmp\1\drk2.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\lsgusou.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\tamxygxxoorn.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %ALLUSERSPROFILE%\xywnqikni & timeout 2 & del /f /q "%TEMP%\lsgusou.exe"' (with hidden window)
- '%WINDIR%\syswow64\cscript.exe' f17.vbs //e:vbscript //NOLOGO
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\V1fWHfGiPBX & timeout 2 & del /f /q "%TEMP%\sib83D1.tmp\1\drk2.exe"
- '%WINDIR%\syswow64\timeout.exe' 2
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\lsgusou.exe"
- '%WINDIR%\syswow64\cmd.exe' /c start "" "%TEMP%\tamxygxxoorn.exe"
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %ALLUSERSPROFILE%\xywnqikni & timeout 2 & del /f /q "%TEMP%\lsgusou.exe"