Technical Information
- <SYSTEM32>\extrac32.exe
- %WINDIR%\windowsshell054531.log
- %WINDIR%\windowssystemupdate266.log
- '47.#8.35.46':36281
- '<LOCALNET>..16.0':51420
- '<LOCALNET>..16.2':51420
- '<LOCALNET>..16.1':51420
- '<LOCALNET>..16.4':51420
- '<LOCALNET>..16.3':51420
- '<LOCALNET>..16.6':51420
- '<LOCALNET>..16.8':51420
- '<LOCALNET>..16.9':51420
- '<LOCALNET>..16.10':51420
- '<LOCALNET>..16.5':51420
- '<LOCALNET>..16.15':51420
- '<LOCALNET>..16.17':51420
- '<LOCALNET>..16.13':51420
- '<LOCALNET>..16.11':51420
- '<LOCALNET>..16.21':51420
- '<LOCALNET>..16.12':51420
- '<LOCALNET>..16.14':51420
- '<LOCALNET>..16.23':51420
- '<LOCALNET>..16.16':51420
- '<LOCALNET>..16.25':51420
- '<LOCALNET>..16.18':51420
- '<LOCALNET>..16.27':51420
- '<LOCALNET>..16.20':51420
- '<LOCALNET>..16.22':51420
- '<LOCALNET>..16.7':51420
- '<LOCALNET>..16.19':51420
- '<LOCALNET>..16.29':51420
- '<LOCALNET>..16.24':51420
- '<LOCALNET>..16.26':51420
- '<LOCALNET>..16.28':51420
- '<LOCALNET>..16.30':51420
- '<LOCALNET>..16.32':51420
- '<LOCALNET>..16.34':51420
- '<LOCALNET>..16.36':51420
- '<LOCALNET>..16.40':51420
- '<LOCALNET>..16.31':51420
- '<LOCALNET>..16.42':51420
- '<LOCALNET>..16.33':51420
- '<LOCALNET>..16.44':51420
- '<LOCALNET>..16.35':51420
- '<LOCALNET>..16.37':51420
- '<LOCALNET>..16.39':51420
- '<LOCALNET>..16.41':51420
- '<LOCALNET>..16.46':51420
- '<LOCALNET>..16.48':51420
- '<LOCALNET>..16.50':51420
- '<LOCALNET>..16.52':51420
- '<LOCALNET>..16.54':51420
- '<LOCALNET>..16.56':51420
- '<LOCALNET>..16.58':51420
- '<LOCALNET>..16.60':51420
- '<LOCALNET>..16.43':51420
- '<LOCALNET>..16.45':51420
- '<LOCALNET>..16.47':51420
- '<LOCALNET>..16.62':51420
- '<LOCALNET>..16.49':51420
- '<LOCALNET>..16.64':51420
- '<LOCALNET>..16.51':51420
- '<LOCALNET>..16.68':51420
- '<LOCALNET>..16.53':51420
- '<LOCALNET>..16.70':51420
- '<LOCALNET>..16.66':51420
- '<LOCALNET>..16.72':51420
- '<LOCALNET>..16.55':51420
- '<LOCALNET>..16.57':51420
- '<LOCALNET>..16.74':51420
- '<LOCALNET>..16.59':51420
- '<LOCALNET>..16.76':51420
- '<LOCALNET>..16.78':51420
- '<LOCALNET>..16.61':51420
- '<LOCALNET>..16.63':51420
- '<LOCALNET>..16.65':51420
- '<LOCALNET>..16.67':51420
- '<LOCALNET>..16.73':51420
- '<LOCALNET>..16.75':51420
- '<LOCALNET>..16.77':51420
- '<LOCALNET>..16.79':51420
- '<LOCALNET>..16.81':51420
- '<LOCALNET>..16.83':51420
- '<LOCALNET>..16.85':51420
- '<LOCALNET>..16.87':51420
- '<LOCALNET>..16.89':51420
- '<LOCALNET>..16.91':51420
- '<LOCALNET>..16.93':51420
- '<LOCALNET>..16.97':51420
- '<LOCALNET>..16.99':51420
- '<LOCALNET>..16.69':51420
- '<LOCALNET>..16.101':51420
- '<LOCALNET>..16.103':51420
- '<LOCALNET>..16.71':51420
- '<LOCALNET>..16.95':51420
- '<LOCALNET>..16.107':51420
- '<LOCALNET>..16.109':51420
- '<LOCALNET>..16.111':51420
- '<LOCALNET>..16.113':51420
- '<LOCALNET>..16.115':51420
- '<LOCALNET>..16.117':51420
- '<LOCALNET>..16.121':51420
- '<LOCALNET>..16.123':51420
- '<LOCALNET>..16.125':51420
- '<LOCALNET>..16.127':51420
- '<LOCALNET>..16.119':51420
- '<LOCALNET>..16.129':51420
- '<LOCALNET>..16.131':51420
- '<LOCALNET>..16.133':51420
- '<LOCALNET>..16.135':51420
- '<LOCALNET>..16.137':51420
- '<LOCALNET>..16.141':51420
- '<LOCALNET>..16.143':51420
- '<LOCALNET>..16.145':51420
- '<LOCALNET>..16.147':51420
- '<LOCALNET>..16.149':51420
- '<LOCALNET>..16.151':51420
- '<LOCALNET>..16.153':51420
- '<LOCALNET>..16.155':51420
- '<LOCALNET>..16.157':51420
- '<LOCALNET>..16.159':51420
- '<LOCALNET>..16.161':51420
- '<LOCALNET>..16.165':51420
- '<LOCALNET>..16.167':51420
- '<LOCALNET>..16.169':51420
- '<LOCALNET>..16.171':51420
- '<LOCALNET>..16.173':51420
- '<LOCALNET>..16.175':51420
- '<LOCALNET>..16.177':51420
- '<LOCALNET>..16.179':51420
- '<LOCALNET>..16.181':51420
- '<LOCALNET>..16.183':51420
- '<LOCALNET>..16.82':51420
- '<LOCALNET>..16.185':51420
- '<LOCALNET>..16.189':51420
- '<LOCALNET>..16.187':51420
- '<LOCALNET>..16.191':51420
- '<LOCALNET>..16.193':51420
- '<LOCALNET>..16.195':51420
- '<LOCALNET>..16.197':51420
- '<LOCALNET>..16.199':51420
- '<LOCALNET>..16.163':51420
- '<LOCALNET>..16.105':51420
- '<LOCALNET>..16.139':51420
- '<LOCALNET>..16.84':51420
- '<LOCALNET>..16.86':51420
- '<LOCALNET>..16.88':51420
- '<LOCALNET>..16.94':51420
- '<LOCALNET>..16.98':51420
- '<LOCALNET>..16.90':51420
- '<LOCALNET>..16.100':51420
- '<LOCALNET>..16.104':51420
- '<LOCALNET>..16.102':51420
- '<LOCALNET>..16.106':51420
- '<LOCALNET>..16.114':51420
- '<LOCALNET>..16.116':51420
- '<LOCALNET>..16.112':51420
- '<LOCALNET>..16.118':51420
- '<LOCALNET>..16.120':51420
- '<LOCALNET>..16.122':51420
- '<LOCALNET>..16.124':51420
- '<LOCALNET>..16.126':51420
- '<LOCALNET>..16.128':51420
- '<LOCALNET>..16.132':51420
- '<LOCALNET>..16.134':51420
- '<LOCALNET>..16.130':51420
- '<LOCALNET>..16.136':51420
- '<LOCALNET>..16.38':51420
- '<LOCALNET>..16.108':51420
- '<LOCALNET>..16.144':51420
- '<LOCALNET>..16.146':51420
- '<LOCALNET>..16.140':51420
- '<LOCALNET>..16.150':51420
- '<LOCALNET>..16.148':51420
- '<LOCALNET>..16.158':51420
- '<LOCALNET>..16.154':51420
- '<LOCALNET>..16.160':51420
- '<LOCALNET>..16.152':51420
- '<LOCALNET>..16.166':51420
- '<LOCALNET>..16.168':51420
- '<LOCALNET>..16.164':51420
- '<LOCALNET>..16.172':51420
- '<LOCALNET>..16.174':51420
- '<LOCALNET>..16.170':51420
- '<LOCALNET>..16.176':51420
- '<LOCALNET>..16.180':51420
- '<LOCALNET>..16.178':51420
- '<LOCALNET>..16.182':51420
- '<LOCALNET>..16.80':51420
- '<LOCALNET>..16.92':51420
- '<LOCALNET>..16.110':51420
- '<LOCALNET>..16.138':51420
- '<LOCALNET>..16.184':51420
- '<LOCALNET>..16.186':51420
- '<LOCALNET>..16.190':51420
- '<LOCALNET>..16.192':51420
- '<LOCALNET>..16.188':51420
- '<LOCALNET>..16.194':51420
- '<LOCALNET>..16.196':51420
- '<LOCALNET>..16.96':51420
- '<LOCALNET>..16.156':51420
- '<LOCALNET>..16.142':51420
- '<LOCALNET>..16.162':51420
- '<LOCALNET>..16.198':51420
- '43.##9.192.68':46283
- '47.##.113.58':46282
- '47.#8.35.46':36281
- '47.##.113.58':46282
- '255.255.255.255':58053
- '<SYSTEM32>\extrac32.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\extrac32.exe"
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)