Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- app2.exe
- %HOMEPATH%\desktop\february_catalogue__2015.doc
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\nwfieldnotes1966.docx
- %HOMEPATH%\desktop\weeklysheet1215.doc
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %TEMP%\app1.exe
- %TEMP%\rarsfx0\system.io.compression.dll
- %TEMP%\rarsfx0\system.memory.dll
- %TEMP%\rarsfx0\system.memory.xml
- %TEMP%\rarsfx0\system.numerics.vectors.dll
- %TEMP%\rarsfx0\system.numerics.vectors.xml
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.dll
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.xml
- %TEMP%\rarsfx0\x64\sqlite.interop.dll
- %APPDATA%\factoryprotectionsolution\mercurys.dll
- %TEMP%\rarsfx0\x86\sqlite.interop.dll
- %TEMP%\rarsfx0\bouncycastle.crypto.xml
- %TEMP%\rarsfx0\newtonsoft.json.dll
- %TEMP%\rarsfx0\newtonsoft.json.xml
- %APPDATA%\stealer\desktop\docs\february_catalogue__2015.doc
- %APPDATA%\stealer\desktop\docs\lisp_success.doc
- %APPDATA%\stealer\desktop\docs\nwfieldnotes1966.docx
- %APPDATA%\stealer\desktop\docs\weeklysheet1215.doc
- %APPDATA%\stealer\pcinfo.txt
- %TEMP%\rarsfx0\system.data.sqlite.dll
- %TEMP%\rarsfx0\system.data.sqlite.xml
- %TEMP%\rarsfx0\system.buffers.xml
- %TEMP%\rarsfx0\system.buffers.dll
- %TEMP%\rarsfx0\svc_host.pdb
- %APPDATA%\factoryprotectionsolution\factoryprotectiontool.exe
- %APPDATA%\factoryprotectionsolution\png.xs.dll
- %APPDATA%\factoryprotectionsolution\zlib.xs.dll
- %APPDATA%\factoryprotectionsolution\config.xml
- %APPDATA%\factoryprotectionsolution\freeglut.dll
- %APPDATA%\factoryprotectionsolution\libgraph23.dll
- %APPDATA%\factoryprotectionsolution\libopennas2.dll
- %APPDATA%\factoryprotectionsolution\license.txt
- %APPDATA%\stealer\screenshot.png
- %TEMP%\rarsfx0\bouncycastle.crypto.dll
- %APPDATA%\factoryprotectionsolution\lua52.dll
- %APPDATA%\factoryprotectionsolution\msvcp140_2.dll
- %APPDATA%\factoryprotectionsolution\php_sodium.dll
- %APPDATA%\factoryprotectionsolution\zlib1.dll
- %TEMP%\steam.exe
- %HOMEPATH%\09368f65836
- %TEMP%\sbvc.exe
- %TEMP%\rarsfx0\svc_host.exe
- %TEMP%\rarsfx0\svc_host.exe.config
- %TEMP%\app2.exe
- %APPDATA%\factoryprotectionsolution\msvcm90.dll
- %APPDATA%\95.211.190.198.zip
- %TEMP%\app1.exe
- %TEMP%\steam.exe
- %APPDATA%\95.211.190.198.zip
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.xml
- %TEMP%\rarsfx0\system.runtime.compilerservices.unsafe.dll
- %TEMP%\rarsfx0\system.numerics.vectors.xml
- %TEMP%\rarsfx0\system.numerics.vectors.dll
- %TEMP%\rarsfx0\system.memory.xml
- %TEMP%\rarsfx0\system.memory.dll
- %TEMP%\rarsfx0\system.io.compression.dll
- %TEMP%\rarsfx0\system.data.sqlite.xml
- %TEMP%\rarsfx0\system.data.sqlite.dll
- %TEMP%\rarsfx0\system.buffers.xml
- %TEMP%\rarsfx0\system.buffers.dll
- %TEMP%\rarsfx0\x64\sqlite.interop.dll
- %TEMP%\rarsfx0\svc_host.pdb
- %TEMP%\rarsfx0\svc_host.exe
- %TEMP%\rarsfx0\newtonsoft.json.xml
- %TEMP%\rarsfx0\newtonsoft.json.dll
- %TEMP%\rarsfx0\bouncycastle.crypto.xml
- %TEMP%\rarsfx0\bouncycastle.crypto.dll
- %APPDATA%\stealer\screenshot.png
- %APPDATA%\stealer\pcinfo.txt
- %APPDATA%\stealer\desktop\docs\weeklysheet1215.doc
- %APPDATA%\stealer\desktop\docs\nwfieldnotes1966.docx
- %APPDATA%\stealer\desktop\docs\lisp_success.doc
- %APPDATA%\stealer\desktop\docs\february_catalogue__2015.doc
- %TEMP%\rarsfx0\svc_host.exe.config
- %TEMP%\rarsfx0\x86\sqlite.interop.dll
- 'u1#######ft.ha004.t.justns.ru':80
- 'microsoft.com':80
- '17#.#7.141.153':80
- 'ch####p.dyndns.org':80
- 'ip##fo.io':80
- '51.##4.187.177':3705
- 'ap#.ip.sb':443
- 'ip###ger.org':80
- 'ip###ger.org':443
- http://u1#######ft.ha004.t.justns.ru/@RalphStormy.exe
- http://ip##fo.io/95.211.190.198
- http://17#.#7.141.153/log.php
- http://51.###.187.177:3705// via 51.##4.187.177
- DNS ASK u1#######ft.ha004.t.justns.ru
- DNS ASK mm####idbhmibnr.ml
- DNS ASK li##o8.ru
- DNS ASK microsoft.com
- DNS ASK ch####p.dyndns.org
- DNS ASK ip##fo.io
- DNS ASK ap#.ip.sb
- DNS ASK ip###ger.org
- ClassName: '18467-41' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\app1.exe'
- '%APPDATA%\factoryprotectionsolution\factoryprotectiontool.exe'
- '%TEMP%\app2.exe'
- '%TEMP%\steam.exe'
- '%TEMP%\sbvc.exe'
- '%TEMP%\rarsfx0\svc_host.exe'
- '%TEMP%\sbvc.exe' ' (with hidden window)
- '%ALLUSERSPROFILE%\data\database.exe' -epool eth-eu1.nanopool.org:9999 -eworker Worker1 -ewal 0x12e60999128c3015d0F14511E6BD9F0C741494e8 -epsw password666 -ethi 4 -mode 1 -tt 60 -tstop 75 -dbg -1' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'