Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\x.vbs
- <SYSTEM32>\tasks\firefox default browser agent 3267080485e96c02
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -Command Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
- @.cmd
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\nsc256b.tmp
- %TEMP%\7zs0e213a43\sat18d6c4a909af02dc.exe
- %TEMP%\7zs0e213a43\sat18d97f9194.exe
- %TEMP%\7zs0e213a43\sat18ed5ae6b6b55c78.exe
- %TEMP%\7zs0e213a43\setup_install.exe
- %TEMP%\is-829qs.tmp\sat18d6c4a909af02dc.tmp
- %TEMP%\ixp000.tmp\@.cmd
- %TEMP%\ixp000.tmp\@.cm_
- %TEMP%\is-v6p42.tmp\_isetup\_setup64.tmp
- %LOCALAPPDATA%\csidl_
- %LOCALAPPDATA%\csidl_x
- %TEMP%\is-v6p42.tmp\idp.dll
- %TEMP%\is-h7q72.tmp\sat18d6c4a909af02dc.tmp
- %TEMP%\is-vfud8.tmp\_isetup\_setup64.tmp
- %TEMP%\is-vfud8.tmp\idp.dll
- %TEMP%\ubvaqe9.nru
- %TEMP%\7zs0e213a43\sat18c294a5ed10.exe
- %TEMP%\11111.exe
- %TEMP%\7zs0e213a43\sat18acb52ef5.exe
- %TEMP%\7zs0e213a43\sat1891bfc7ad9.exe
- %TEMP%\setup_installer.exe
- %TEMP%\7zs0e213a43\libcurl.dll
- %TEMP%\7zs0e213a43\libcurlpp.dll
- %TEMP%\7zs0e213a43\libgcc_s_dw2-1.dll
- %TEMP%\7zs0e213a43\libstdc++-6.dll
- %TEMP%\7zs0e213a43\libwinpthread-1.dll
- %TEMP%\7zs0e213a43\sat18024ade45160f48.exe
- %TEMP%\7zs0e213a43\sat18040faaecdc7debe.exe
- %TEMP%\7zs0e213a43\sat1815c0be69.exe
- %TEMP%\7zs0e213a43\sat1827ef4cde01.exe
- %TEMP%\7zs0e213a43\sat183c6ee4cba.exe
- %TEMP%\7zs0e213a43\sat1848e75d56600.exe
- %TEMP%\7zs0e213a43\sat1857e947d4a48.exe
- %TEMP%\7zs0e213a43\sat1870afde446f79.exe
- %TEMP%\7zs0e213a43\sat188cf8d51ab590a.exe
- %TEMP%\7zs0e213a43\sat18aa41685e.exe
- %APPDATA%\tdseswf
- %LOCALAPPDATA%\csidl_
- %LOCALAPPDATA%\csidl_x
- %APPDATA%\tdseswf
- %TEMP%\ixp000.tmp\@.cm_
- %TEMP%\ixp000.tmp\@.cmd
- %TEMP%\is-v6p42.tmp\idp.dll
- %TEMP%\is-v6p42.tmp\_isetup\_setup64.tmp
- %TEMP%\7zs0e213a43\sat1891bfc7ad9.exe
- %TEMP%\11111.exe
- 'localhost':49186
- 'localhost':49188
- '21#.#93.30.45':80
- 'li###ncode.com':443
- 'ip###ger.org':443
- 'no#.social':443
- 'c.#m':443
- 'ip##pi.com':80
- '45.##4.225.57':80
- 'pa###bin.com':443
- http://ip##pi.com/json/
- 'localhost':49186
- 'localhost':49188
- 'localhost':49189
- 'li###ncode.com':443
- 'ip###ger.org':443
- 'no#.social':443
- 'pa###bin.com':443
- DNS ASK ra###nori.xyz
- DNS ASK gp.###ebuy768.com
- DNS ASK li###ncode.com
- DNS ASK ip###ger.org
- DNS ASK no#.social
- DNS ASK c.#m
- DNS ASK ip##pi.com
- DNS ASK pa###bin.com
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\setup_installer.exe'
- '%TEMP%\7zs0e213a43\sat18d6c4a909af02dc.exe' /SILENT
- '%TEMP%\ixp000.tmp\@.cmd'
- '%TEMP%\is-829qs.tmp\sat18d6c4a909af02dc.tmp' /SL5="$F010C,870426,780800,%TEMP%\7zS0E213A43\Sat18d6c4a909af02dc.exe"
- '%TEMP%\7zs0e213a43\sat1857e947d4a48.exe'
- '%TEMP%\7zs0e213a43\sat18d97f9194.exe'
- '%TEMP%\7zs0e213a43\sat18d6c4a909af02dc.exe'
- '%TEMP%\7zs0e213a43\sat18aa41685e.exe' -u
- '%TEMP%\7zs0e213a43\sat1870afde446f79.exe'
- '%TEMP%\7zs0e213a43\sat1848e75d56600.exe'
- '%TEMP%\7zs0e213a43\sat1827ef4cde01.exe'
- '%TEMP%\7zs0e213a43\sat18024ade45160f48.exe'
- '%TEMP%\7zs0e213a43\sat1891bfc7ad9.exe'
- '%TEMP%\7zs0e213a43\sat18040faaecdc7debe.exe'
- '%TEMP%\7zs0e213a43\sat18aa41685e.exe'
- '%TEMP%\7zs0e213a43\sat18acb52ef5.exe'
- '%TEMP%\7zs0e213a43\sat1815c0be69.exe'
- '%TEMP%\7zs0e213a43\sat18ed5ae6b6b55c78.exe'
- '%TEMP%\7zs0e213a43\sat183c6ee4cba.exe' /mixtwo
- '%TEMP%\7zs0e213a43\sat188cf8d51ab590a.exe'
- '%TEMP%\7zs0e213a43\sat18c294a5ed10.exe'
- '%TEMP%\7zs0e213a43\setup_install.exe'
- '%TEMP%\is-h7q72.tmp\sat18d6c4a909af02dc.tmp' /SL5="$20276,870426,780800,%TEMP%\7zS0E213A43\Sat18d6c4a909af02dc.exe" /SILENT
- '%TEMP%\11111.exe' /CookiesFile "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies" /scookiestxt %TEMP%\fj4ghga23_fsa.txt
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Set-MpPreference -DisableRealtimeMonitoring $true -SubmitSamplesConsent NeverSend -MAPSReporting Disable
- '%WINDIR%\syswow64\cmd.exe' /c Sat1891bfc7ad9.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\IXP000.TMP\@.cmd",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c Sat1857e947d4a48.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat1848e75d56600.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat18d6c4a909af02dc.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat18040faaecdc7debe.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat1827ef4cde01.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat18d97f9194.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat1815c0be69.exe
- '%WINDIR%\syswow64\msiexec.exe' /Y .\UBVaQE9.NrU
- '%WINDIR%\syswow64\cmd.exe' /c Sat18024ade45160f48.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat183c6ee4cba.exe /mixtwo
- '%WINDIR%\syswow64\cmd.exe' /c Sat18ed5ae6b6b55c78.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat1870afde446f79.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat188cf8d51ab590a.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat18c294a5ed10.exe
- '%WINDIR%\syswow64\cmd.exe' /c powershell -inputformat none -outputformat none -NonInteractive -Command Add-MpPreference -ExclusionPath "%LOCALAPPDATA%\Temp"
- '%WINDIR%\syswow64\cmd.exe' /c Sat18aa41685e.exe
- '%WINDIR%\syswow64\cmd.exe' /c Sat18acb52ef5.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo on error resume next:CreateObject("WScript.Shell").Run "%TEMP%\IXP000.TMP\@.cmd",1: >"%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\x.vbs"' (with hidden window)
- '%TEMP%\11111.exe' /CookiesFile "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies" /scookiestxt %TEMP%\fj4ghga23_fsa.txt' (with hidden window)
- '%TEMP%\11111.exe' /stab %TEMP%\fj4ghga23_fsa.txt' (with hidden window)