Technical Information
- <SYSTEM32>\deviceproperties.exe
- %WINDIR%\windowsshell3675.log
- %WINDIR%\windowssystemupdate33.log
- '47.#8.35.46':36281
- '<LOCALNET>..29.0':51420
- '<LOCALNET>..29.3':51420
- '<LOCALNET>..29.2':51420
- '<LOCALNET>..29.1':51420
- '<LOCALNET>..29.4':51420
- '<LOCALNET>..29.6':51420
- '<LOCALNET>..29.8':51420
- '<LOCALNET>..29.10':51420
- '<LOCALNET>..29.14':51420
- '<LOCALNET>..29.7':51420
- '<LOCALNET>..29.18':51420
- '<LOCALNET>..29.22':51420
- '<LOCALNET>..29.24':51420
- '<LOCALNET>..29.26':51420
- '<LOCALNET>..29.28':51420
- '<LOCALNET>..29.32':51420
- '<LOCALNET>..29.34':51420
- '<LOCALNET>..29.36':51420
- '<LOCALNET>..29.38':51420
- '<LOCALNET>..29.40':51420
- '<LOCALNET>..29.42':51420
- '<LOCALNET>..29.44':51420
- '<LOCALNET>..29.9':51420
- '<LOCALNET>..29.46':51420
- '<LOCALNET>..29.5':51420
- '<LOCALNET>..29.48':51420
- '<LOCALNET>..29.11':51420
- '<LOCALNET>..29.52':51420
- '<LOCALNET>..29.13':51420
- '<LOCALNET>..29.58':51420
- '<LOCALNET>..29.60':51420
- '<LOCALNET>..29.17':51420
- '<LOCALNET>..29.19':51420
- '<LOCALNET>..29.21':51420
- '<LOCALNET>..29.23':51420
- '<LOCALNET>..29.62':51420
- '<LOCALNET>..29.25':51420
- '<LOCALNET>..29.27':51420
- '<LOCALNET>..29.29':51420
- '<LOCALNET>..29.33':51420
- '<LOCALNET>..29.64':51420
- '<LOCALNET>..29.66':51420
- '<LOCALNET>..29.68':51420
- '<LOCALNET>..29.70':51420
- '<LOCALNET>..29.72':51420
- '<LOCALNET>..29.74':51420
- '<LOCALNET>..29.76':51420
- '<LOCALNET>..29.78':51420
- '<LOCALNET>..29.80':51420
- '<LOCALNET>..29.82':51420
- '<LOCALNET>..29.86':51420
- '<LOCALNET>..29.84':51420
- '<LOCALNET>..29.88':51420
- '<LOCALNET>..29.90':51420
- '<LOCALNET>..29.39':51420
- '<LOCALNET>..29.92':51420
- '<LOCALNET>..29.43':51420
- '<LOCALNET>..29.45':51420
- '<LOCALNET>..29.47':51420
- '<LOCALNET>..29.49':51420
- '<LOCALNET>..29.96':51420
- '<LOCALNET>..29.51':51420
- '<LOCALNET>..29.53':51420
- '<LOCALNET>..29.98':51420
- '<LOCALNET>..29.55':51420
- '<LOCALNET>..29.57':51420
- '<LOCALNET>..29.30':51420
- '<LOCALNET>..29.59':51420
- '<LOCALNET>..29.100':51420
- '<LOCALNET>..29.61':51420
- '<LOCALNET>..29.102':51420
- '<LOCALNET>..29.63':51420
- '<LOCALNET>..29.65':51420
- '<LOCALNET>..29.104':51420
- '<LOCALNET>..29.67':51420
- '<LOCALNET>..29.106':51420
- '<LOCALNET>..29.54':51420
- '<LOCALNET>..29.69':51420
- '<LOCALNET>..29.56':51420
- '<LOCALNET>..29.108':51420
- '<LOCALNET>..29.71':51420
- '<LOCALNET>..29.110':51420
- '<LOCALNET>..29.112':51420
- '<LOCALNET>..29.87':51420
- '<LOCALNET>..29.73':51420
- '<LOCALNET>..29.75':51420
- '<LOCALNET>..29.77':51420
- '<LOCALNET>..29.114':51420
- '<LOCALNET>..29.81':51420
- '<LOCALNET>..29.83':51420
- '<LOCALNET>..29.50':51420
- '<LOCALNET>..29.91':51420
- '<LOCALNET>..29.118':51420
- '<LOCALNET>..29.89':51420
- '<LOCALNET>..29.120':51420
- '<LOCALNET>..29.95':51420
- '<LOCALNET>..29.124':51420
- '<LOCALNET>..29.126':51420
- '<LOCALNET>..29.101':51420
- '<LOCALNET>..29.128':51420
- '<LOCALNET>..29.103':51420
- '<LOCALNET>..29.105':51420
- '<LOCALNET>..29.109':51420
- '<LOCALNET>..29.130':51420
- '<LOCALNET>..29.111':51420
- '<LOCALNET>..29.113':51420
- '<LOCALNET>..29.132':51420
- '<LOCALNET>..29.115':51420
- '<LOCALNET>..29.93':51420
- '<LOCALNET>..29.119':51420
- '<LOCALNET>..29.125':51420
- '<LOCALNET>..29.127':51420
- '<LOCALNET>..29.129':51420
- '<LOCALNET>..29.134':51420
- '<LOCALNET>..29.117':51420
- '<LOCALNET>..29.123':51420
- '<LOCALNET>..29.31':51420
- '<LOCALNET>..29.131':51420
- '<LOCALNET>..29.133':51420
- '<LOCALNET>..29.122':51420
- '<LOCALNET>..29.137':51420
- '<LOCALNET>..29.139':51420
- '<LOCALNET>..29.141':51420
- '<LOCALNET>..29.143':51420
- '<LOCALNET>..29.145':51420
- '<LOCALNET>..29.147':51420
- '<LOCALNET>..29.151':51420
- '<LOCALNET>..29.153':51420
- '<LOCALNET>..29.155':51420
- '<LOCALNET>..29.161':51420
- '<LOCALNET>..29.163':51420
- '<LOCALNET>..29.37':51420
- '<LOCALNET>..29.136':51420
- '<LOCALNET>..29.97':51420
- '<LOCALNET>..29.138':51420
- '<LOCALNET>..29.157':51420
- '<LOCALNET>..29.140':51420
- '<LOCALNET>..29.165':51420
- '<LOCALNET>..29.167':51420
- '<LOCALNET>..29.169':51420
- '<LOCALNET>..29.173':51420
- '<LOCALNET>..29.175':51420
- '<LOCALNET>..29.142':51420
- '<LOCALNET>..29.177':51420
- '<LOCALNET>..29.144':51420
- '<LOCALNET>..29.179':51420
- '<LOCALNET>..29.146':51420
- '<LOCALNET>..29.181':51420
- '<LOCALNET>..29.152':51420
- '<LOCALNET>..29.183':51420
- '<LOCALNET>..29.185':51420
- '<LOCALNET>..29.187':51420
- '<LOCALNET>..29.189':51420
- '<LOCALNET>..29.191':51420
- '<LOCALNET>..29.193':51420
- '<LOCALNET>..29.154':51420
- '<LOCALNET>..29.149':51420
- '<LOCALNET>..29.197':51420
- '<LOCALNET>..29.41':51420
- '<LOCALNET>..29.79':51420
- '<LOCALNET>..29.15':51420
- '<LOCALNET>..29.35':51420
- '<LOCALNET>..29.85':51420
- '<LOCALNET>..29.159':51420
- '<LOCALNET>..29.171':51420
- '<LOCALNET>..29.199':51420
- '<LOCALNET>..29.20':51420
- '<LOCALNET>..29.99':51420
- '<LOCALNET>..29.148':51420
- '<LOCALNET>..29.107':51420
- '<LOCALNET>..29.12':51420
- '<LOCALNET>..29.121':51420
- '<LOCALNET>..29.135':51420
- '<LOCALNET>..29.195':51420
- '<LOCALNET>..29.156':51420
- '<LOCALNET>..29.158':51420
- '<LOCALNET>..29.160':51420
- '<LOCALNET>..29.162':51420
- '<LOCALNET>..29.164':51420
- '<LOCALNET>..29.94':51420
- '<LOCALNET>..29.150':51420
- '<LOCALNET>..29.168':51420
- '<LOCALNET>..29.166':51420
- '<LOCALNET>..29.172':51420
- '<LOCALNET>..29.178':51420
- '<LOCALNET>..29.174':51420
- '<LOCALNET>..29.180':51420
- '<LOCALNET>..29.184':51420
- '<LOCALNET>..29.182':51420
- '<LOCALNET>..29.176':51420
- '<LOCALNET>..29.116':51420
- '<LOCALNET>..29.186':51420
- '<LOCALNET>..29.188':51420
- '<LOCALNET>..29.190':51420
- '<LOCALNET>..29.192':51420
- '<LOCALNET>..29.194':51420
- '<LOCALNET>..29.16':51420
- '<LOCALNET>..29.196':51420
- '<LOCALNET>..29.198':51420
- '<LOCALNET>..29.170':51420
- '43.##9.192.68':46283
- '47.##.113.58':46282
- '47.#8.35.46':36283
- '47.#8.35.46':36281
- '47.##.113.58':46282
- '47.#8.35.46':36283
- '255.255.255.255':16800
- '<SYSTEM32>\deviceproperties.exe'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\deviceproperties.exe"
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)