Technical Information
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] 'Web Event Logger' = '{79FEACFF-FFCE-815E-A900-316290B5B738}'
- <Current directory>\log\log.txt
- <Current directory>\recovered_payload\recovered_payload.exe
- %WINDIR%\syswow64\ijlkcqof.exe
- %WINDIR%\syswow64\plmnnfhg.dll
- %WINDIR%\syswow64\lgijfgdi.exe
- %WINDIR%\syswow64\pckhfd32.dll
- %WINDIR%\syswow64\lgncaf32.exe
- %WINDIR%\syswow64\dfpfajgi.dll
- %WINDIR%\syswow64\mcddfgeh.exe
- %WINDIR%\syswow64\nalkbmln.dll
- %WINDIR%\syswow64\mloeemjf.exe
- %WINDIR%\syswow64\bflbmk32.dll
- %WINDIR%\syswow64\mgkckj32.exe
- %WINDIR%\syswow64\pjkegc32.dll
- %WINDIR%\syswow64\njnibepp.exe
- %WINDIR%\syswow64\ddifob32.dll
- %WINDIR%\syswow64\bogfak32.exe
- %WINDIR%\syswow64\hngpmeqb.dll
- %WINDIR%\syswow64\cmifdcgc.exe
- %WINDIR%\syswow64\okgcli32.dll
- %WINDIR%\syswow64\eiienf32.exe
- %WINDIR%\syswow64\kifimeqn.dll
- %WINDIR%\syswow64\feobbj32.exe
- %WINDIR%\syswow64\nemdde32.dll
- %WINDIR%\syswow64\gahplk32.exe
- %WINDIR%\syswow64\eogmpp32.dll
- %WINDIR%\syswow64\gamigjod.exe
- %WINDIR%\syswow64\pcdhjn32.dll
- %WINDIR%\syswow64\hnfgbkbf.exe
- %WINDIR%\syswow64\heckhg32.dll
- %WINDIR%\syswow64\hpilif32.exe
- %WINDIR%\syswow64\ghddngao.dll
- %WINDIR%\syswow64\hjdnhk32.exe
- %WINDIR%\syswow64\maegflmg.dll
- %WINDIR%\syswow64\ifmkbl32.exe
- %WINDIR%\syswow64\dddfmk32.dll
- %WINDIR%\syswow64\iqiihi32.exe
- %WINDIR%\syswow64\bicjfb32.dll
- %WINDIR%\syswow64\jmbfcj32.exe
- %WINDIR%\syswow64\lpbdjh32.dll
- %WINDIR%\syswow64\jikcmk32.exe
- %WINDIR%\syswow64\dhannmhn.dll
- %WINDIR%\syswow64\jipmhjcn.exe
- %WINDIR%\syswow64\gfabqjak.dll
- %WINDIR%\syswow64\keijckfo.exe
- %WINDIR%\syswow64\oqkklemb.dll
- %WINDIR%\syswow64\kabhmkjq.exe
- %WINDIR%\syswow64\gkddfphi.dll
- %WINDIR%\syswow64\llneci32.exe
- %WINDIR%\syswow64\ebpbqpdc.dll
- %WINDIR%\syswow64\leigbnik.exe
- %WINDIR%\syswow64\jgnplljb.dll
- %WINDIR%\syswow64\ldqphjlp.exe
- %WINDIR%\syswow64\bkdbkoil.dll
- %WINDIR%\syswow64\mpjnckpa.exe
- %WINDIR%\syswow64\ilceih32.dll
- %WINDIR%\syswow64\mnpkbo32.exe
- %WINDIR%\syswow64\oceplg32.dll
- %WINDIR%\syswow64\mlgdik32.exe
- %WINDIR%\syswow64\ohdagm32.dll
- %WINDIR%\syswow64\nfbfgp32.exe
- %WINDIR%\syswow64\mecdhiba.dll
- %WINDIR%\syswow64\nbkcaq32.exe
- %WINDIR%\syswow64\egagfbgp.dll
- %WINDIR%\syswow64\egfedm32.exe
- %WINDIR%\syswow64\ehcook32.dll
- %WINDIR%\syswow64\emhggcho.exe
- %WINDIR%\syswow64\jcckdh32.dll
- %WINDIR%\syswow64\gdalcabg.exe
- %WINDIR%\syswow64\eljkilhg.dll
- %WINDIR%\syswow64\gpkinafi.exe
- %WINDIR%\syswow64\nciema32.dll
- %WINDIR%\syswow64\gelkah32.exe
- %WINDIR%\syswow64\ldqjlpdo.dll
- %WINDIR%\syswow64\hknmdnjm.exe
- %WINDIR%\syswow64\pmlfbodf.dll
- %WINDIR%\syswow64\ikdcem32.exe
- %WINDIR%\syswow64\cgakqb32.dll
- %WINDIR%\syswow64\ignqon32.exe
- %WINDIR%\syswow64\khpmok32.dll
- %WINDIR%\syswow64\icgnjn32.exe
- %WINDIR%\syswow64\bioomdpm.dll
- %WINDIR%\syswow64\jgicca32.exe
- %WINDIR%\syswow64\mgeahg32.dll
- %WINDIR%\syswow64\jjlijmie.exe
- %WINDIR%\syswow64\nnjedl32.dll
- %WINDIR%\syswow64\kfefemmg.exe
- %WINDIR%\syswow64\geioha32.dll
- %WINDIR%\syswow64\kemplipl.exe
- %WINDIR%\syswow64\dpflemjm.dll
- %WINDIR%\syswow64\klkbcbcd.exe
- %WINDIR%\syswow64\hjpdgc32.dll
- %WINDIR%\syswow64\lmahfjem.exe
- %WINDIR%\syswow64\pkmoap32.dll
- %WINDIR%\syswow64\lijeakhn.exe
- %WINDIR%\syswow64\knidei32.dll
- %WINDIR%\syswow64\mioolj32.exe
- %WINDIR%\syswow64\clfhmbmc.dll
- %WINDIR%\syswow64\mampfl32.exe
- %WINDIR%\syswow64\mnginc32.dll
- %WINDIR%\syswow64\npdjmh32.exe
- %WINDIR%\syswow64\jhdfko32.dll
- %WINDIR%\syswow64\nnjgklom.exe
- %WINDIR%\syswow64\nccgjb32.dll
- %WINDIR%\syswow64\nehhen32.exe
- %WINDIR%\syswow64\hddhjc32.dll
- %WINDIR%\syswow64\nhiagihg.exe
- '<Current directory>\recovered_payload\recovered_payload.exe'
- '%WINDIR%\syswow64\ijlkcqof.exe'
- '%WINDIR%\syswow64\lgijfgdi.exe'
- '%WINDIR%\syswow64\lgncaf32.exe'
- '%WINDIR%\syswow64\mcddfgeh.exe'
- '%WINDIR%\syswow64\mloeemjf.exe'
- '%WINDIR%\syswow64\mgkckj32.exe'
- '%WINDIR%\syswow64\njnibepp.exe'
- '%WINDIR%\syswow64\bogfak32.exe'
- '%WINDIR%\syswow64\cmifdcgc.exe'
- '%WINDIR%\syswow64\eiienf32.exe'
- '%WINDIR%\syswow64\feobbj32.exe'
- '%WINDIR%\syswow64\gahplk32.exe'
- '%WINDIR%\syswow64\gamigjod.exe'
- '%WINDIR%\syswow64\hnfgbkbf.exe'
- '%WINDIR%\syswow64\hpilif32.exe'
- '%WINDIR%\syswow64\hjdnhk32.exe'
- '%WINDIR%\syswow64\ifmkbl32.exe'
- '%WINDIR%\syswow64\iqiihi32.exe'
- '%WINDIR%\syswow64\jmbfcj32.exe'
- '%WINDIR%\syswow64\jikcmk32.exe'
- '%WINDIR%\syswow64\jipmhjcn.exe'
- '%WINDIR%\syswow64\keijckfo.exe'
- '%WINDIR%\syswow64\kabhmkjq.exe'
- '%WINDIR%\syswow64\llneci32.exe'
- '%WINDIR%\syswow64\leigbnik.exe'
- '%WINDIR%\syswow64\ldqphjlp.exe'
- '%WINDIR%\syswow64\mpjnckpa.exe'
- '%WINDIR%\syswow64\mnpkbo32.exe'
- '%WINDIR%\syswow64\mlgdik32.exe'
- '%WINDIR%\syswow64\nfbfgp32.exe'
- '%WINDIR%\syswow64\nbkcaq32.exe'
- '%WINDIR%\syswow64\egfedm32.exe'
- '%WINDIR%\syswow64\emhggcho.exe'
- '%WINDIR%\syswow64\gdalcabg.exe'
- '%WINDIR%\syswow64\gpkinafi.exe'
- '%WINDIR%\syswow64\gelkah32.exe'
- '%WINDIR%\syswow64\hknmdnjm.exe'
- '%WINDIR%\syswow64\ikdcem32.exe'
- '%WINDIR%\syswow64\ignqon32.exe'
- '%WINDIR%\syswow64\icgnjn32.exe'
- '%WINDIR%\syswow64\jgicca32.exe'
- '%WINDIR%\syswow64\jjlijmie.exe'
- '%WINDIR%\syswow64\kfefemmg.exe'
- '%WINDIR%\syswow64\kemplipl.exe'
- '%WINDIR%\syswow64\klkbcbcd.exe'
- '%WINDIR%\syswow64\lmahfjem.exe'
- '%WINDIR%\syswow64\lijeakhn.exe'
- '%WINDIR%\syswow64\mioolj32.exe'
- '%WINDIR%\syswow64\mampfl32.exe'
- '%WINDIR%\syswow64\npdjmh32.exe'
- '%WINDIR%\syswow64\nnjgklom.exe'
- '%WINDIR%\syswow64\nehhen32.exe'
- '%WINDIR%\syswow64\ijlkcqof.exe' ' (with hidden window)
- '%WINDIR%\syswow64\lgijfgdi.exe' ' (with hidden window)
- '%WINDIR%\syswow64\lgncaf32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mcddfgeh.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mloeemjf.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mgkckj32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\njnibepp.exe' ' (with hidden window)
- '%WINDIR%\syswow64\bogfak32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmifdcgc.exe' ' (with hidden window)
- '%WINDIR%\syswow64\eiienf32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\feobbj32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\gahplk32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\gamigjod.exe' ' (with hidden window)
- '%WINDIR%\syswow64\hnfgbkbf.exe' ' (with hidden window)
- '%WINDIR%\syswow64\hpilif32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\hjdnhk32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\ifmkbl32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\iqiihi32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\jmbfcj32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\jikcmk32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\jipmhjcn.exe' ' (with hidden window)
- '%WINDIR%\syswow64\keijckfo.exe' ' (with hidden window)
- '%WINDIR%\syswow64\kabhmkjq.exe' ' (with hidden window)
- '%WINDIR%\syswow64\llneci32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\leigbnik.exe' ' (with hidden window)
- '%WINDIR%\syswow64\ldqphjlp.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mpjnckpa.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mnpkbo32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mlgdik32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\nfbfgp32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\nbkcaq32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\egfedm32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\emhggcho.exe' ' (with hidden window)
- '%WINDIR%\syswow64\gdalcabg.exe' ' (with hidden window)
- '%WINDIR%\syswow64\gpkinafi.exe' ' (with hidden window)
- '%WINDIR%\syswow64\gelkah32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\hknmdnjm.exe' ' (with hidden window)
- '%WINDIR%\syswow64\ikdcem32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\ignqon32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\icgnjn32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\jgicca32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\jjlijmie.exe' ' (with hidden window)
- '%WINDIR%\syswow64\kfefemmg.exe' ' (with hidden window)
- '%WINDIR%\syswow64\kemplipl.exe' ' (with hidden window)
- '%WINDIR%\syswow64\klkbcbcd.exe' ' (with hidden window)
- '%WINDIR%\syswow64\lmahfjem.exe' ' (with hidden window)
- '%WINDIR%\syswow64\lijeakhn.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mioolj32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\mampfl32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\npdjmh32.exe' ' (with hidden window)
- '%WINDIR%\syswow64\nnjgklom.exe' ' (with hidden window)
- '%WINDIR%\syswow64\nehhen32.exe' ' (with hidden window)