Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{HA4B6GN8-LUQB-E64P-4HHI-UUIANTXV8YOM}' = '"%APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.exe"'
- <LS_APPDATA>\google\chrome\user data\default\cookies
- <LS_APPDATA>\google\chrome\user data\default\login data
- <LS_APPDATA>\google\chrome\user data\default\web data
- %APPDATA%\amd64_netfx4-system.serviceprocess\enu_8fe9758a3a5467072535
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe.1
- %TEMP%\aut2.tmp
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\information.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\cookies\mozilla firefox (6).txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\d877f783d5d3ef8c1
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\инструкция по установке.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\d877f783d5d3ef8c\map0
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\инструкция по установке.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\config\config.vdf
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\screen.jpg
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.sqlite3.module.dll
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.sqlite3.module.dll.1
- %TEMP%\aut1.tmp
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\config\dialogconfig.vdf
- %APPDATA%\amd64_netfx4-system.serviceprocess\enu_8fe9758a3a5467072535.7z
- %TEMP%\aut1.tmp
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.sqlite3.module.dll.1
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.sqlite3.module.dll
- %TEMP%\aut2.tmp
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe.1
- %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\information.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\screen.jpg
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\d877f783d5d3ef8c1
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\инструкция по установке.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\telegram\d877f783d5d3ef8c\map0
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\инструкция по установке.txt
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\config\config.vdf
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\steam\config\dialogconfig.vdf
- %APPDATA%\amd64_netfx4-system.serviceprocess\1\cookies\mozilla firefox (6).txt
- from <Full path to file> to %APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.exe
- '18#.#77.84.249':9976
- DNS ASK ap#.##legram.org
- DNS ASK ip##i.co
- '%APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe' a -y -mx9 -ssw "%APPDATA%\amd64_netfx4-system.serviceprocess\ENU_8FE9758A3A5467072535.7z" "%APPDATA%\amd64_netfx4-system.serviceprocess\1\*"
- '%APPDATA%\amd64_netfx4-system.serviceprocess\ncrypt.module.exe' a -y -mx9 -ssw "%APPDATA%\amd64_netfx4-system.serviceprocess\ENU_8FE9758A3A5467072535.7z" "%APPDATA%\amd64_netfx4-system.serviceprocess\1\*"' (with hidden window)
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\amd64_netfx4-system.serviceprocess"' (with hidden window)
- '<SYSTEM32>\attrib.exe' +s +h "%APPDATA%\amd64_netfx4-system.serviceprocess"