Technical Information
- [HKLM\System\CurrentControlSet\Services\WinDivert] 'ImagePath' = 'C:\bin\WinDivert64.sys'
- 'WinDivert' C:\bin\WinDivert64.sys
- %LOCALAPPDATA%\turbo.net\sandbox\xsandbox.bin.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\dpier.exe\dpier.exe.manifest.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\winws.exe\winws.exe.manifest.__tmp__
- %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@windir@\xsxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest
- %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest.__meta__.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest
- %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe.__tmp__
- %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe.manifest.__tmp__
- %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@windir@\xsxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest
- %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest.__meta__.__tmp__
- %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest
- %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe.__tmp__
- %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe.manifest.__tmp__
- %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@sysdrive@\bin\cygwin1.dll
- %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@sysdrive@\bin\cygwin1.dll.__meta__.__tmp__
- from %LOCALAPPDATA%\turbo.net\sandbox\xsandbox.bin.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\xsandbox.bin
- from %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\dpier.exe\dpier.exe.manifest.__tmp__ to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\dpier.exe\dpier.exe.manifest
- from %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest.__tmp__ to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest
- from %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest.__tmp__ to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest
- from %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\winws.exe\winws.exe.manifest.__tmp__ to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\winws.exe\winws.exe.manifest
- from %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@windir@\xsxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest
- from %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest.__meta__.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\dpier.exe_0x7dc2a87402ee1802d2be6e95a522f337.1.manifest.__meta__
- from %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe
- from %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe.manifest.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe.manifest
- from %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@windir@\xsxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest to %TEMP%\turbo\cache\0xce4c58b5ac02c829\sxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest
- from %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest.__meta__.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@windir@\xsxs\manifests\winws.exe_0x644a94557df02266fc36a933be5ccd93.1.manifest.__meta__
- from %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe
- from %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe.manifest.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe.manifest
- from %LOCALAPPDATA%\turbo.net\sandbox\local\temp\@sysdrive@\bin\cygwin1.dll to %LOCALAPPDATA%\turbo.net\sandbox\local\modified\@sysdrive@\bin\cygwin1.dll
- from %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@sysdrive@\bin\cygwin1.dll.__meta__.__tmp__ to %LOCALAPPDATA%\turbo.net\sandbox\local\meta\@sysdrive@\bin\cygwin1.dll.__meta__
- 'st###.turbo.net':443
- 'st###.turbo.net':443
- DNS ASK st###.turbo.net
- 'localhost':61549
- '%LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x517d62a07abc3ac9\dpier.exe'
- '%LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe' /864A627C-C6B2-464A-AA13-25D62F282BD8
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=1.#.1.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=1.#.1.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=1.#.0.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=1.#.0.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=8.#.8.8 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=8.#.8.8 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=8.#.4.4 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=8.#.4.4 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=9.#.9.9 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=9.#.9.9 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=14#.#12.112.112 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\netsh.exe' dns add encryption server=14#.#12.112.112 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Ethernet" static 1.#.1.1 validate=no
- '<SYSTEM32>\netsh.exe' interface ip set dns name="Ethernet" static 1.#.1.1 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Ethernet" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Ethernet" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Ethernet" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Ethernet" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Ethernet" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Wi-Fi" static 1.#.1.1 validate=no
- '<SYSTEM32>\netsh.exe' interface ip set dns name="Wi-Fi" static 1.#.1.1 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Wi-Fi" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Wi-Fi" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Wi-Fi" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Wi-Fi" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Wi-Fi" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Беспроводная сеть" static 1.#.1.1 validate=no
- '<SYSTEM32>\netsh.exe' interface ip set dns name="Беспроводная сеть" static 1.#.1.1 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Беспроводная сеть" 1.#.0.1 index=2 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Беспроводная сеть" 8.#.8.8 index=3 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Беспроводная сеть" 8.#.4.4 index=4 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Беспроводная сеть" 9.#.9.9 index=5 validate=no
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\netsh.exe' interface ip add dns name="Беспроводная сеть" 14#.#12.112.112 index=6 validate=no
- '<SYSTEM32>\cmd.exe' /c ipconfig /flushdns
- '<SYSTEM32>\ipconfig.exe' /flushdns
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv6 set global randomizeidentifiers=disabled
- '<SYSTEM32>\netsh.exe' interface ipv6 set global randomizeidentifiers=disabled
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv6 set privacy state=disabled
- '<SYSTEM32>\netsh.exe' interface ipv6 set privacy state=disabled
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=1.#.1.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=1.#.0.1 dohtemplate=https://cloudflare-dns.com/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=8.#.8.8 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=8.#.4.4 dohtemplate=https://dns.google/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=9.#.9.9 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh dns add encryption server=14#.#12.112.112 dohtemplate=https://dns.quad9.net/dns-query autoupgrade=yes udpfallback=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Ethernet" static 1.#.1.1 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 1.#.0.1 index=2 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 8.#.8.8 index=3 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 8.#.4.4 index=4 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 9.#.9.9 index=5 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Ethernet" 14#.#12.112.112 index=6 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Wi-Fi" static 1.#.1.1 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 1.#.0.1 index=2 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 8.#.8.8 index=3 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 8.#.4.4 index=4 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 9.#.9.9 index=5 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Wi-Fi" 14#.#12.112.112 index=6 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip set dns name="Беспроводная сеть" static 1.#.1.1 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 1.#.0.1 index=2 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 8.#.8.8 index=3 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 8.#.4.4 index=4 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 9.#.9.9 index=5 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ip add dns name="Беспроводная сеть" 14#.#12.112.112 index=6 validate=no' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ipconfig /flushdns' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv6 set global randomizeidentifiers=disabled' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c netsh interface ipv6 set privacy state=disabled' (with hidden window)
- '%LOCALAPPDATA%\turbo.net\sandbox\local\stubexe\0x558f97042313081a\winws.exe' /864A627C-C6B2-464A-AA13-25D62F282BD8' (with hidden window)