Technical Information
- <SYSTEM32>\tasks\credential manager ui host
- %TEMP%\_mei9562\vcruntime140.dll
- %TEMP%\_mei9562\vcruntime140_1.dll
- %TEMP%\_mei9562\_asyncio.pyd
- %TEMP%\_mei9562\_brotli.cp313-win_amd64.pyd
- %TEMP%\_mei9562\_bz2.pyd
- %TEMP%\_mei9562\_cffi_backend.cp313-win_amd64.pyd
- %TEMP%\_mei9562\_ctypes.pyd
- %TEMP%\_mei9562\_decimal.pyd
- %TEMP%\_mei9562\_hashlib.pyd
- %TEMP%\_mei9562\_lzma.pyd
- %TEMP%\_mei9562\_multiprocessing.pyd
- %TEMP%\_mei9562\_overlapped.pyd
- %TEMP%\_mei9562\_queue.pyd
- %TEMP%\_mei9562\_socket.pyd
- %TEMP%\_mei9562\_ssl.pyd
- %TEMP%\_mei9562\_uuid.pyd
- %TEMP%\_mei9562\_wmi.pyd
- %TEMP%\_mei9562\aiohttp\_http_parser.cp313-win_amd64.pyd
- %TEMP%\_mei9562\aiohttp\_http_writer.cp313-win_amd64.pyd
- %TEMP%\_mei9562\aiohttp\_websocket\mask.cp313-win_amd64.pyd
- %TEMP%\_mei9562\aiohttp\_websocket\reader_c.cp313-win_amd64.pyd
- %TEMP%\_mei9562\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei9562\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei9562\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei9562\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei9562\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei9562\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei9562\attrs-25.3.0.dist-info\installer
- %TEMP%\_mei9562\attrs-25.3.0.dist-info\metadata
- %TEMP%\_mei9562\attrs-25.3.0.dist-info\record
- %TEMP%\_mei9562\attrs-25.3.0.dist-info\wheel
- %TEMP%\_mei9562\attrs-25.3.0.dist-info\licenses\license
- %TEMP%\_mei9562\base_library.zip
- %TEMP%\_mei9562\certifi\cacert.pem
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\installer
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\license
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\metadata
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\record
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\wheel
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\entry_points.txt
- %TEMP%\_mei9562\cffi-1.17.1.dist-info\top_level.txt
- %TEMP%\_mei9562\charset_normalizer\md.cp313-win_amd64.pyd
- %TEMP%\_mei9562\charset_normalizer\md__mypyc.cp313-win_amd64.pyd
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\installer
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\metadata
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\record
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\wheel
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\licenses\license
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\licenses\license.apache
- %TEMP%\_mei9562\cryptography-45.0.6.dist-info\licenses\license.bsd
- %TEMP%\_mei9562\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei9562\dnspython-2.7.0.dist-info\installer
- %TEMP%\_mei9562\dnspython-2.7.0.dist-info\metadata
- %TEMP%\_mei9562\dnspython-2.7.0.dist-info\record
- %TEMP%\_mei9562\dnspython-2.7.0.dist-info\wheel
- %TEMP%\_mei9562\dnspython-2.7.0.dist-info\licenses\license
- %TEMP%\_mei9562\frozenlist\_frozenlist.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\installer
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\metadata
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\record
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\wheel
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\entry_points.txt
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\licenses\license
- %TEMP%\_mei9562\gevent-25.4.2.dist-info\top_level.txt
- %TEMP%\_mei9562\gevent\_gevent_c_abstract_linkable.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_greenlet_primitives.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_hub_local.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_hub_primitives.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_ident.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_imap.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_semaphore.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_tracer.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_c_waiter.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_cevent.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_cgreenlet.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_clocal.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\_gevent_cqueue.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\libev\corecext.cp313-win_amd64.pyd
- %TEMP%\_mei9562\gevent\libuv\_corecffi.pyd
- %TEMP%\_mei9562\gevent\resolver\cares.cp313-win_amd64.pyd
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\installer
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\metadata
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\record
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\wheel
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\licenses\license
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\licenses\license.psf
- %TEMP%\_mei9562\greenlet-3.2.1.dist-info\top_level.txt
- %TEMP%\_mei9562\greenlet\_greenlet.cp313-win_amd64.pyd
- %TEMP%\_mei9562\libcrypto-3.dll
- %TEMP%\_mei9562\libffi-8.dll
- %TEMP%\_mei9562\libssl-3.dll
- %TEMP%\_mei9562\multidict\_multidict.cp313-win_amd64.pyd
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\delvewheel
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\installer
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\license.txt
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\metadata
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\record
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\wheel
- %TEMP%\_mei9562\numpy-2.2.6.dist-info\entry_points.txt
- %TEMP%\_mei9562\propcache\_helpers_c.cp313-win_amd64.pyd
- %TEMP%\_mei9562\psutil\_psutil_windows.pyd
- %TEMP%\_mei9562\pycparser-2.22.dist-info\installer
- %TEMP%\_mei9562\pycparser-2.22.dist-info\license
- %TEMP%\_mei9562\pycparser-2.22.dist-info\metadata
- %TEMP%\_mei9562\pycparser-2.22.dist-info\record
- %TEMP%\_mei9562\pycparser-2.22.dist-info\wheel
- %TEMP%\_mei9562\pycparser-2.22.dist-info\top_level.txt
- %TEMP%\_mei9562\pyexpat.pyd
- %TEMP%\_mei9562\python3.dll
- %TEMP%\_mei9562\python313.dll
- %TEMP%\_mei9562\pywin32_system32\pywintypes313.dll
- %TEMP%\_mei9562\select.pyd
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\installer
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\metadata
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\record
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\wheel
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\entry_points.txt
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\licenses\license
- %TEMP%\_mei9562\setuptools-80.1.0.dist-info\top_level.txt
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\installer
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\license
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\metadata
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\record
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\wheel
- %TEMP%\_mei9562\setuptools\_vendor\importlib_metadata-8.0.0.dist-info\top_level.txt
- %TEMP%\_mei9562\setuptools\_vendor\jaraco\text\lorem ipsum.txt
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\installer
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\license.txt
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\metadata
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\record
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\wheel
- %TEMP%\_mei9562\setuptools\_vendor\wheel-0.45.1.dist-info\entry_points.txt
- %TEMP%\_mei9562\ucrtbase.dll
- %TEMP%\_mei9562\unicodedata.pyd
- %TEMP%\_mei9562\win32\win32api.pyd
- %TEMP%\_mei9562\yarl\_quoting_c.cp313-win_amd64.pyd
- %TEMP%\_mei9562\zope.event-5.0.dist-info\installer
- %TEMP%\_mei9562\zope.event-5.0.dist-info\license.txt
- %TEMP%\_mei9562\zope.event-5.0.dist-info\metadata
- %TEMP%\_mei9562\zope.event-5.0.dist-info\record
- %TEMP%\_mei9562\zope.event-5.0.dist-info\wheel
- %TEMP%\_mei9562\zope.event-5.0.dist-info\namespace_packages.txt
- %TEMP%\_mei9562\zope.event-5.0.dist-info\top_level.txt
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\installer
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\license.txt
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\metadata
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\record
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\wheel
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\namespace_packages.txt
- %TEMP%\_mei9562\zope.interface-7.2.dist-info\top_level.txt
- %TEMP%\_mei9562\zope\interface\_zope_interface_coptimizations.cp313-win_amd64.pyd
- %TEMP%\_mei9562\zstandard\_cffi.cp313-win_amd64.pyd
- %TEMP%\_mei9562\zstandard\backend_c.cp313-win_amd64.pyd
- %APPDATA%\microsoft\credentials\credman.exe
- 'gi##.###hubusercontent.com':443
- 'va#####win.gl.at.ply.gg':3753
- 'gi##.###hubusercontent.com':443
- DNS ASK gi##.###hubusercontent.com
- DNS ASK va#####win.gl.at.ply.gg
- '<SYSTEM32>\cmd.exe' /c "ver"
- '<SYSTEM32>\cmd.exe' /c "schtasks /create /tn "Credential Manager UI Host" /tr "%APPDATA%\Microsoft\Credentials\credman.exe" /sc onlogon /rl highest /f"
- '<SYSTEM32>\schtasks.exe' /create /tn "Credential Manager UI Host" /tr "%APPDATA%\Microsoft\Credentials\credman.exe" /sc onlogon /rl highest /f
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "schtasks /create /tn "Credential Manager UI Host" /tr "%APPDATA%\Microsoft\Credentials\credman.exe" /sc onlogon /rl highest /f"' (with hidden window)