Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'SystemUpdateService' = '"%APPDATA%\Microsoft\System\sysupdate.exe" --silent'
- %TEMP%\_mei33442\sdl2.dll
- %TEMP%\_mei33442\sdl2_image.dll
- %TEMP%\_mei33442\sdl2_mixer.dll
- %TEMP%\_mei33442\sdl2_ttf.dll
- %TEMP%\_mei33442\vcruntime140.dll
- %TEMP%\_mei33442\vcruntime140_1.dll
- %TEMP%\_mei33442\_asyncio.pyd
- %TEMP%\_mei33442\_bz2.pyd
- %TEMP%\_mei33442\_cffi_backend.cp313-win_amd64.pyd
- %TEMP%\_mei33442\_ctypes.pyd
- %TEMP%\_mei33442\_decimal.pyd
- %TEMP%\_mei33442\_hashlib.pyd
- %TEMP%\_mei33442\_lzma.pyd
- %TEMP%\_mei33442\_multiprocessing.pyd
- %TEMP%\_mei33442\_overlapped.pyd
- %TEMP%\_mei33442\_queue.pyd
- %TEMP%\_mei33442\_socket.pyd
- %TEMP%\_mei33442\_ssl.pyd
- %TEMP%\_mei33442\_wmi.pyd
- %TEMP%\_mei33442\base_library.zip
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\installer
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\metadata
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\record
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\wheel
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\licenses\license
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei33442\cryptography-45.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei33442\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei33442\freetype.dll
- %TEMP%\_mei33442\libcrypto-3.dll
- %TEMP%\_mei33442\libffi-8.dll
- %TEMP%\_mei33442\libjpeg-9.dll
- %TEMP%\_mei33442\libmodplug-1.dll
- %TEMP%\_mei33442\libogg-0.dll
- %TEMP%\_mei33442\libopus-0.dll
- %TEMP%\_mei33442\libopusfile-0.dll
- %TEMP%\_mei33442\libpng16-16.dll
- %TEMP%\_mei33442\libssl-3.dll
- %TEMP%\_mei33442\libtiff-5.dll
- %TEMP%\_mei33442\libwebp-7.dll
- %TEMP%\_mei33442\portmidi.dll
- %TEMP%\_mei33442\psutil\_psutil_windows.pyd
- %TEMP%\_mei33442\pyexpat.pyd
- %TEMP%\_mei33442\pygame\sdl2.dll
- %TEMP%\_mei33442\pygame\sdl2_image.dll
- %TEMP%\_mei33442\pygame\sdl2_mixer.dll
- %TEMP%\_mei33442\pygame\sdl2_ttf.dll
- %TEMP%\_mei33442\pygame\_freetype.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\base.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\bufferproxy.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\color.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\constants.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\display.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\draw.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\event.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\font.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\freesansbold.ttf
- %TEMP%\_mei33442\pygame\freetype.dll
- %TEMP%\_mei33442\pygame\image.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\imageext.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\joystick.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\key.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\libjpeg-9.dll
- %TEMP%\_mei33442\pygame\libogg-0.dll
- %TEMP%\_mei33442\pygame\libopus-0.dll
- %TEMP%\_mei33442\pygame\libpng16-16.dll
- %TEMP%\_mei33442\pygame\mask.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\math.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\mixer.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\mixer_music.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\mouse.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\pixelarray.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\pixelcopy.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\pygame_icon.bmp
- %TEMP%\_mei33442\pygame\rect.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\rwobject.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\scrap.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\surface.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\surflock.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\time.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\transform.cp313-win_amd64.pyd
- %TEMP%\_mei33442\pygame\zlib1.dll
- %TEMP%\_mei33442\python3.dll
- %TEMP%\_mei33442\python313.dll
- %TEMP%\_mei33442\pywin32_system32\pywintypes313.dll
- %TEMP%\_mei33442\select.pyd
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei33442\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei33442\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei33442\unicodedata.pyd
- %TEMP%\_mei33442\win32\win32api.pyd
- %TEMP%\_mei33442\win32\win32process.pyd
- %TEMP%\_mei33442\win32\win32security.pyd
- %TEMP%\_mei33442\zlib1.dll
- %APPDATA%\ce850545\sys_1757665644.dat
- %APPDATA%\microsoft\system\sysupdate.exe
- 'localhost':49692
- '88.##8.163.195':1337
- '<SYSTEM32>\cmd.exe' /c "ver"
- '<SYSTEM32>\cmd.exe' /c "reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService"
- '<SYSTEM32>\reg.exe' query HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService
- '<SYSTEM32>\cmd.exe' /c "reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService /t REG_SZ /d "\"%APPDATA%\Microsoft\System\sysupdate.exe\" --silent" /f"
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService /t REG_SZ /d "\"%APPDATA%\Microsoft\System\sysupdate.exe\" --silent" /f
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v SystemUpdateService /t REG_SZ /d "\"%APPDATA%\Microsoft\System\sysupdate.exe\" --silent" /f"' (with hidden window)