Technical Information
- <SYSTEM32>\subst.exe
- %WINDIR%\windowsshell2013.log
- %WINDIR%\windowssystemupdate86.log
- '47.#8.35.46':36281
- '<LOCALNET>..108.1':51420
- '<LOCALNET>..108.3':51420
- '<LOCALNET>..108.5':51420
- '<LOCALNET>..108.0':51420
- '<LOCALNET>..108.9':51420
- '<LOCALNET>..108.11':51420
- '<LOCALNET>..108.2':51420
- '<LOCALNET>..108.23':51420
- '<LOCALNET>..108.6':51420
- '<LOCALNET>..108.25':51420
- '<LOCALNET>..108.27':51420
- '<LOCALNET>..108.17':51420
- '<LOCALNET>..108.19':51420
- '<LOCALNET>..108.21':51420
- '<LOCALNET>..108.15':51420
- '<LOCALNET>..108.8':51420
- '<LOCALNET>..108.29':51420
- '<LOCALNET>..108.10':51420
- '<LOCALNET>..108.12':51420
- '<LOCALNET>..108.31':51420
- '<LOCALNET>..108.33':51420
- '<LOCALNET>..108.35':51420
- '<LOCALNET>..108.13':51420
- '<LOCALNET>..108.7':51420
- '<LOCALNET>..108.37':51420
- '<LOCALNET>..108.14':51420
- '<LOCALNET>..108.18':51420
- '<LOCALNET>..108.22':51420
- '<LOCALNET>..108.4':51420
- '<LOCALNET>..108.16':51420
- '<LOCALNET>..108.26':51420
- '<LOCALNET>..108.20':51420
- '<LOCALNET>..108.28':51420
- '<LOCALNET>..108.30':51420
- '<LOCALNET>..108.34':51420
- '<LOCALNET>..108.32':51420
- '<LOCALNET>..108.36':51420
- '<LOCALNET>..108.40':51420
- '<LOCALNET>..108.42':51420
- '<LOCALNET>..108.46':51420
- '<LOCALNET>..108.44':51420
- '<LOCALNET>..108.48':51420
- '<LOCALNET>..108.50':51420
- '<LOCALNET>..108.52':51420
- '<LOCALNET>..108.54':51420
- '<LOCALNET>..108.56':51420
- '<LOCALNET>..108.61':51420
- '<LOCALNET>..108.63':51420
- '<LOCALNET>..108.65':51420
- '<LOCALNET>..108.67':51420
- '<LOCALNET>..108.69':51420
- '<LOCALNET>..108.71':51420
- '<LOCALNET>..108.58':51420
- '<LOCALNET>..108.39':51420
- '<LOCALNET>..108.41':51420
- '<LOCALNET>..108.43':51420
- '<LOCALNET>..108.45':51420
- '<LOCALNET>..108.24':51420
- '<LOCALNET>..108.49':51420
- '<LOCALNET>..108.47':51420
- '<LOCALNET>..108.53':51420
- '<LOCALNET>..108.60':51420
- '<LOCALNET>..108.55':51420
- '<LOCALNET>..108.57':51420
- '<LOCALNET>..108.59':51420
- '<LOCALNET>..108.38':51420
- '<LOCALNET>..108.51':51420
- '<LOCALNET>..108.75':51420
- '<LOCALNET>..108.77':51420
- '<LOCALNET>..108.83':51420
- '<LOCALNET>..108.87':51420
- '<LOCALNET>..108.89':51420
- '<LOCALNET>..108.91':51420
- '<LOCALNET>..108.95':51420
- '<LOCALNET>..108.97':51420
- '<LOCALNET>..108.99':51420
- '<LOCALNET>..108.101':51420
- '<LOCALNET>..108.85':51420
- '<LOCALNET>..108.115':51420
- '<LOCALNET>..108.117':51420
- '<LOCALNET>..108.121':51420
- '<LOCALNET>..108.123':51420
- '<LOCALNET>..108.125':51420
- '<LOCALNET>..108.127':51420
- '<LOCALNET>..108.129':51420
- '<LOCALNET>..108.131':51420
- '<LOCALNET>..108.81':51420
- '<LOCALNET>..108.119':51420
- '<LOCALNET>..108.135':51420
- '<LOCALNET>..108.137':51420
- '<LOCALNET>..108.73':51420
- '<LOCALNET>..108.79':51420
- '<LOCALNET>..108.133':51420
- '<LOCALNET>..108.62':51420
- '<LOCALNET>..108.66':51420
- '<LOCALNET>..108.64':51420
- '<LOCALNET>..108.93':51420
- '<LOCALNET>..108.70':51420
- '<LOCALNET>..108.72':51420
- '<LOCALNET>..108.74':51420
- '<LOCALNET>..108.76':51420
- '<LOCALNET>..108.68':51420
- '<LOCALNET>..108.78':51420
- '<LOCALNET>..108.80':51420
- '<LOCALNET>..108.82':51420
- '<LOCALNET>..108.84':51420
- '<LOCALNET>..108.86':51420
- '<LOCALNET>..108.88':51420
- '<LOCALNET>..108.90':51420
- '<LOCALNET>..108.92':51420
- '<LOCALNET>..108.96':51420
- '<LOCALNET>..108.103':51420
- '<LOCALNET>..108.109':51420
- '<LOCALNET>..108.107':51420
- '<LOCALNET>..108.113':51420
- '<LOCALNET>..108.105':51420
- '<LOCALNET>..108.108':51420
- '<LOCALNET>..108.100':51420
- '<LOCALNET>..108.102':51420
- '<LOCALNET>..108.104':51420
- '<LOCALNET>..108.139':51420
- '<LOCALNET>..108.141':51420
- '<LOCALNET>..108.106':51420
- '<LOCALNET>..108.110':51420
- '<LOCALNET>..108.112':51420
- '<LOCALNET>..108.111':51420
- '<LOCALNET>..108.114':51420
- '<LOCALNET>..108.116':51420
- '<LOCALNET>..108.147':51420
- '<LOCALNET>..108.118':51420
- '<LOCALNET>..108.98':51420
- '<LOCALNET>..108.149':51420
- '<LOCALNET>..108.143':51420
- '<LOCALNET>..108.145':51420
- '<LOCALNET>..108.151':51420
- '<LOCALNET>..108.153':51420
- '<LOCALNET>..108.155':51420
- '<LOCALNET>..108.157':51420
- '<LOCALNET>..108.159':51420
- '<LOCALNET>..108.161':51420
- '<LOCALNET>..108.163':51420
- '<LOCALNET>..108.120':51420
- '<LOCALNET>..108.122':51420
- '<LOCALNET>..108.124':51420
- '<LOCALNET>..108.165':51420
- '<LOCALNET>..108.126':51420
- '<LOCALNET>..108.167':51420
- '<LOCALNET>..108.169':51420
- '<LOCALNET>..108.171':51420
- '<LOCALNET>..108.128':51420
- '<LOCALNET>..108.173':51420
- '<LOCALNET>..108.175':51420
- '<LOCALNET>..108.177':51420
- '<LOCALNET>..108.193':51420
- '<LOCALNET>..108.130':51420
- '<LOCALNET>..108.94':51420
- '<LOCALNET>..108.132':51420
- '<LOCALNET>..108.136':51420
- '<LOCALNET>..108.134':51420
- '<LOCALNET>..108.140':51420
- '<LOCALNET>..108.144':51420
- '<LOCALNET>..108.142':51420
- '<LOCALNET>..108.146':51420
- '<LOCALNET>..108.148':51420
- '<LOCALNET>..108.183':51420
- '<LOCALNET>..108.150':51420
- '<LOCALNET>..108.187':51420
- '<LOCALNET>..108.138':51420
- '<LOCALNET>..108.189':51420
- '<LOCALNET>..108.191':51420
- '<LOCALNET>..108.152':51420
- '<LOCALNET>..108.179':51420
- '<LOCALNET>..108.185':51420
- '<LOCALNET>..108.195':51420
- '<LOCALNET>..108.154':51420
- '<LOCALNET>..108.156':51420
- '<LOCALNET>..108.158':51420
- '<LOCALNET>..108.162':51420
- '<LOCALNET>..108.160':51420
- '<LOCALNET>..108.164':51420
- '<LOCALNET>..108.166':51420
- '<LOCALNET>..108.168':51420
- '<LOCALNET>..108.172':51420
- '<LOCALNET>..108.170':51420
- '<LOCALNET>..108.174':51420
- '<LOCALNET>..108.176':51420
- '<LOCALNET>..108.178':51420
- '<LOCALNET>..108.180':51420
- '<LOCALNET>..108.182':51420
- '<LOCALNET>..108.184':51420
- '<LOCALNET>..108.186':51420
- '<LOCALNET>..108.188':51420
- '<LOCALNET>..108.190':51420
- '<LOCALNET>..108.192':51420
- '<LOCALNET>..108.194':51420
- '<LOCALNET>..108.181':51420
- '<LOCALNET>..108.199':51420
- '<LOCALNET>..108.196':51420
- '<LOCALNET>..108.197':51420
- '<LOCALNET>..108.198':51420
- '43.##9.192.68':46283
- '47.#8.35.46':36281
- '255.255.255.255':39573
- '<SYSTEM32>\subst.exe'
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<SYSTEM32>\subst.exe"
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)