Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\smartclock.lnk
- <SYSTEM32>\tasks\smart clock
- '%WINDIR%\syswow64\taskkill.exe' /im "<File name>.exe" /f
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\mozilla\firefox\profiles.ini
- %TEMP%\{x4gs-rnnas-czsq-svpli}\48092484683.exe
- %TEMP%\tfxxw0k\files_\cookies\mozilla_firefox.txt
- %TEMP%\tfxxw0k\_files\_screen_desktop.jpeg
- %TEMP%\tfxxw0k\_files\_information.txt
- %TEMP%\tfxxw0k\files_\screenshot.jpg
- %TEMP%\tfxxw0k\files_\system_info.txt
- %TEMP%\tfxxw0k\dsbpjlly6iocr.zip
- %TEMP%\tfxxw0k\llg8thx0d.zip
- %TEMP%\filett.exe
- %TEMP%\nsn1b00.tmp\uac.dll
- %ProgramFiles(x86)%\foler\olader\acppage.dll
- %ProgramFiles(x86)%\foler\olader\adprovider.dll
- %ProgramFiles(x86)%\foler\olader\acledit.dll
- %TEMP%\namoi\four.exe
- %TEMP%\namoi\vn.exe
- %APPDATA%\smart clock\smartclock.exe
- %TEMP%\ixp000.tmp\esistenza.docm
- %TEMP%\ixp000.tmp\tuo.docm
- %TEMP%\ixp000.tmp\perdonarmi.docm
- %TEMP%\ixp000.tmp\ritorni.docm
- %TEMP%\tfxxw0k\_files\_cookies\mozilla_firefox.txt
- %TEMP%\ixp000.tmp\voto.exe.com
- %TEMP%\tfxxw0k\c5jmn.tmp-shm
- %TEMP%\tfxxw0k\c5jmn.tmp
- %TEMP%\{x4gs-rnnas-czsq-svpli}\15118448512.exe
- %TEMP%\tfxxw0k\rmdja.tmp
- %TEMP%\tfxxw0k\5r5lc.tmp
- %TEMP%\tfxxw0k\oilp.tmp
- %TEMP%\tfxxw0k\pnaai.tmp
- %TEMP%\tfxxw0k\hfofz.tmp
- %TEMP%\tfxxw0k\vs7cy0.tmp
- %TEMP%\tfxxw0k\fef3sr.tmp
- %TEMP%\tfxxw0k\taxj.tmp
- %TEMP%\tfxxw0k\v4cktb.tmp
- %TEMP%\tfxxw0k\_files\_cookies\google_chrome.txt
- %TEMP%\tfxxw0k\files_\cookies\google_chrome.txt
- %TEMP%\tfxxw0k\_files\_allcookies_list.txt
- %TEMP%\tfxxw0k\files_\cookies.txt
- %TEMP%\tfxxw0k\zygxe.tmp
- %TEMP%\tfxxw0k\80pe.tmp
- %TEMP%\tfxxw0k\vwsexn.tmp
- %TEMP%\tfxxw0k\_files\_cookies\opera.txt
- %TEMP%\tfxxw0k\files_\cookies\opera.txt
- %TEMP%\tfxxw0k\fehs8.tmp
- %TEMP%\ixp000.tmp\f
- %TEMP%\tfxxw0k\c5jmn.tmp-shm
- %TEMP%\ixp000.tmp\tuo.docm
- %TEMP%\ixp000.tmp\ritorni.docm
- %TEMP%\ixp000.tmp\perdonarmi.docm
- %TEMP%\ixp000.tmp\f
- %TEMP%\{x4gs-rnnas-czsq-svpli}\15118448512.exe
- %TEMP%\nsn1b00.tmp\uac.dll
- %TEMP%\tfxxw0k\_files\_cookies\opera.txt
- %TEMP%\tfxxw0k\zygxe.tmp
- %TEMP%\tfxxw0k\vwsexn.tmp
- %TEMP%\tfxxw0k\vs7cy0.tmp
- %TEMP%\tfxxw0k\v4cktb.tmp
- %TEMP%\tfxxw0k\taxj.tmp
- %TEMP%\tfxxw0k\rmdja.tmp
- %TEMP%\tfxxw0k\pnaai.tmp
- %TEMP%\tfxxw0k\oilp.tmp
- %TEMP%\tfxxw0k\hfofz.tmp
- %TEMP%\tfxxw0k\files_\cookies.txt
- %TEMP%\tfxxw0k\files_\cookies\opera.txt
- %TEMP%\tfxxw0k\fehs8.tmp
- %TEMP%\tfxxw0k\fef3sr.tmp
- %TEMP%\tfxxw0k\c5jmn.tmp
- %TEMP%\tfxxw0k\80pe.tmp
- %TEMP%\tfxxw0k\5r5lc.tmp
- %TEMP%\ixp000.tmp\esistenza.docm
- %TEMP%\ixp000.tmp\voto.exe.com
- 'gc###rtnrs.top':80
- 'ze###s11.top':80
- '74.##9.195.134':80
- 'ip###ger.org':80
- 'ip###ger.org':443
- 'ly###y12.top':80
- 'mo###r01.top':80
- 'da###a01.top':80
- 'microsoft.com':80
- http://gc###rtnrs.top/dlc/distribution.php?pu#########
- http://gc###rtnrs.top/stats/remember.php?pu###################
- http://ly###y12.top/index.php
- http://mo###r01.top/index.php
- http://74.##9.195.134/
- 'te##te.in':443
- 'ip###ger.org':443
- DNS ASK gc###tnrs.top
- DNS ASK gc###rtnrs.top
- DNS ASK ze###s11.top
- DNS ASK te##te.in
- DNS ASK da##arq.top
- DNS ASK ip###ger.org
- DNS ASK ly###y12.top
- DNS ASK mo###r01.top
- DNS ASK da###a01.top
- DNS ASK microsoft.com
- DNS ASK qW###########iaUAYQcwS.qWasCAAWWRdeHiaUAYQcwS
- ClassName: '' WindowName: ''
- '%TEMP%\{x4gs-rnnas-czsq-svpli}\48092484683.exe'
- '%TEMP%\{x4gs-rnnas-czsq-svpli}\15118448512.exe' /mix
- '%TEMP%\filett.exe'
- '%TEMP%\namoi\four.exe'
- '%TEMP%\namoi\vn.exe'
- '%TEMP%\ixp000.tmp\voto.exe.com' f
- '%APPDATA%\smart clock\smartclock.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\48092484683.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\15118448512.exe" /mix' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\TfxxW0k & timeout 2 & del /f /q "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\15118448512.exe"' (with hidden window)
- '%WINDIR%\syswow64\dllhost.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Ritorni.docm' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\48092484683.exe"
- '%WINDIR%\syswow64\cmd.exe' /c start /I "" "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\15118448512.exe" /mix
- '%WINDIR%\syswow64\cmd.exe' /c rd /s /q %TEMP%\TfxxW0k & timeout 2 & del /f /q "%TEMP%\{x4GS-RNNAS-czsQ-SVplI}\15118448512.exe"
- '%WINDIR%\syswow64\timeout.exe' 2
- '%WINDIR%\syswow64\dllhost.exe'
- '%WINDIR%\syswow64\cmd.exe' /c cmd < Ritorni.docm
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\findstr.exe' /V /R "^LodkRlBSRrPGkJmvfGWoQmKxYYFITWniLRlmgrMsXQEOYkwWHltAFiajnWhTFSYVFIVzmZojUEkZUVvMWJqISXBDmYw$" Esistenza.docm
- '%WINDIR%\syswow64\ping.exe' localhost -n 30
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im "<File name>.exe" /f & erase "<Full path to file>" & exit