Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Asgard' = '%APPDATA%\Asgard.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'b31a22f1834ab1397def821a49aacb59' = '"%APPDATA%\HD Audio Background Process.exe" ..'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'b31a22f1834ab1397def821a49aacb59' = '"%APPDATA%\HD Audio Background Process.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\b31a22f1834ab1397def821a49aacb59.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\HD Audio Background Process.exe" "HD Audio Background Process.exe" ENABLE
- %APPDATA%\mozilla\firefox\profiles.ini
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\asgard.exe
- %TEMP%\costura.system.collections.immutable.dll.compressed
- %TEMP%\costura.system.drawing.common.dll.compressed
- %TEMP%\costura.system.interactive.async.dll.compressed
- %TEMP%\costura.system.linq.async.dll.compressed
- %TEMP%\costura.system.memory.dll.compressed
- %TEMP%\costura.system.numerics.vectors.dll.compressed
- %TEMP%\costura.system.runtime.compilerservices.unsafe.dll.compressed
- %TEMP%\costura.system.threading.tasks.extensions.dll.compressed
- %TEMP%\costura.metadata
- %APPDATA%\hd audio background process.exe
- %TEMP%\ss.png
- %TEMP%\compile.bat
- %TEMP%\compile.vbs
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- %TEMP%\user_passwords.txt
- %TEMP%\cookies3
- %TEMP%\cookies2
- %TEMP%\cookies1
- %TEMP%\costura.system.buffers.dll.compressed
- %TEMP%\user_cookies.txt
- %TEMP%\costura.newtonsoft.json.dll.compressed
- %TEMP%\costura.microsoft.bcl.asyncinterfaces.dll.compressed
- %TEMP%\asgarddd.exe
- %TEMP%\config
- %TEMP%\whysosad
- %TEMP%\rtkbtmanserv.exe
- %TEMP%\bfsvc.cfg
- %TEMP%\xwizard.cfg
- %TEMP%\bfsvc.exe
- %TEMP%\winhlp32.exe
- %TEMP%\hh.exe
- %TEMP%\splwow64.exe
- %TEMP%\xwizard.exe
- %TEMP%\snuvcdsm.exe
- %TEMP%\costura.costura.dll.compressed
- %TEMP%\costura.costura.pdb.compressed
- %TEMP%\costura.discord webhook.dll.compressed
- %TEMP%\costura.discord.net.core.dll.compressed
- %TEMP%\costura.discord.net.rest.dll.compressed
- %TEMP%\costura.discord.net.webhook.dll.compressed
- %TEMP%\costura.dotnetzip.dll.compressed
- %TEMP%\costura.dotnetzip.pdb.compressed
- %TEMP%\costura.leaf.xnet.dll.compressed
- %TEMP%\costura.netstandard.dll.compressed
- %TEMP%\user_history.txt
- %APPDATA%\asgard.exe
- %TEMP%\ss.png
- %TEMP%\costura.discord.net.rest.dll.compressed
- %TEMP%\costura.discord.net.webhook.dll.compressed
- %TEMP%\costura.dotnetzip.dll.compressed
- %TEMP%\costura.dotnetzip.pdb.compressed
- %TEMP%\costura.leaf.xnet.dll.compressed
- %TEMP%\costura.metadata
- %TEMP%\costura.microsoft.bcl.asyncinterfaces.dll.compressed
- %TEMP%\costura.netstandard.dll.compressed
- %TEMP%\costura.newtonsoft.json.dll.compressed
- %TEMP%\costura.system.buffers.dll.compressed
- %TEMP%\costura.system.collections.immutable.dll.compressed
- %TEMP%\costura.system.drawing.common.dll.compressed
- %TEMP%\costura.system.interactive.async.dll.compressed
- %TEMP%\costura.system.linq.async.dll.compressed
- %TEMP%\costura.system.memory.dll.compressed
- %TEMP%\costura.system.numerics.vectors.dll.compressed
- %TEMP%\costura.system.runtime.compilerservices.unsafe.dll.compressed
- %TEMP%\costura.discord.net.core.dll.compressed
- %TEMP%\costura.system.threading.tasks.extensions.dll.compressed
- %TEMP%\costura.discord webhook.dll.compressed
- %TEMP%\costura.costura.dll.compressed
- %TEMP%\compile.bat
- %TEMP%\compile.vbs
- %TEMP%\cookies1
- %TEMP%\cookies2
- %TEMP%\cookies3
- %TEMP%\user_cookies.txt
- %TEMP%\user_history.txt
- %TEMP%\config
- %TEMP%\xwizard.exe
- %TEMP%\splwow64.exe
- %TEMP%\winhlp32.exe
- %TEMP%\snuvcdsm.exe
- %TEMP%\hh.exe
- %TEMP%\bfsvc.cfg
- %TEMP%\bfsvc.exe
- %TEMP%\whysosad
- %TEMP%\xwizard.cfg
- %TEMP%\costura.costura.pdb.compressed
- %TEMP%\rtkbtmanserv.exe
- %TEMP%\compile.bat
- %TEMP%\compile.vbs
- 'ip##pi.com':80
- 'ap###.ipify.org':443
- 'microsoft.com':80
- 'te#####oja.duckdns.org':7777
- 'di##ord.com':443
- http://ip##pi.com/line/?fi############
- 'ap###.ipify.org':443
- 'di##ord.com':443
- DNS ASK ip##pi.com
- DNS ASK it####lvehacker.gq
- DNS ASK ap###.ipify.org
- DNS ASK microsoft.com
- DNS ASK te#####oja.duckdns.org
- DNS ASK di##ord.com
- '%APPDATA%\asgard.exe'
- '%TEMP%\asgarddd.exe'
- '%TEMP%\rtkbtmanserv.exe' ZhXl39BlhP84+Y4kurA8wpehxxqA0X22IMYZ6Vpiqs4osTtObTlNmoxsQ923NyaQRRup0QaqRqAnvUWzSnJOdk+41KkQ7SS1ADi4dzw9pQJQONDKrkJSq1Owj8k3aqB8Hpfjk8OmHAuMq4ESeHyl00LPdjbfFXjcKOhWcZQsxfc=
- '%APPDATA%\hd audio background process.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\compile.vbs"
- '%TEMP%\snuvcdsm.exe' /stext "%TEMP%\user_Passwords.txt"
- '%TEMP%\winhlp32.exe' /stext "%TEMP%\Cookies1"
- '%TEMP%\splwow64.exe' /stext "%TEMP%\Cookies2"
- '%TEMP%\hh.exe' /stext "%TEMP%\Cookies3"
- '%TEMP%\xwizard.exe' /stext "%TEMP%\user_History.txt"
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\HD Audio Background Process.exe" "HD Audio Background Process.exe" ENABLE' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c compile.bat' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 3 & Del "%TEMP%\RtkBtManServ.exe"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c compile.bat
- '<SYSTEM32>\wscript.exe' "%TEMP%\compile.vbs"
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 3 & Del "%TEMP%\RtkBtManServ.exe"
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 3