Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '%APPDATA%\<File name>.exe'
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\dial.bmp
- %HOMEPATH%\desktop\dialmap.bmp
- %HOMEPATH%\desktop\file_p_00000000_1371597592.docx
- %HOMEPATH%\desktop\default.bmp
- %HOMEPATH%\desktop\issi2013_template_for_posters.docx
- %HOMEPATH%\desktop\aoc_saq_d_v3_merchant.docx
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %APPDATA%\<File name>.exe
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\chromium_cookies_xzaovwzjdun_2025-10-16_16.16.51.json
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\gecko_cookies_xzaovwzjdun_2025-10-16_16.16.53.json
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\filezilla_xzaovwzjdun_2025-10-16_16.16.53.txt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dashborder_96.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dial.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dialmap.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\file_p_00000000_1371597592.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\default.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\issi2013_template_for_posters.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\coffee.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\default.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dashborder_120.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dashborder_96.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\toolbar.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\aoc_saq_d_v3_merchant.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\tileimage.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dial.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\february_catalogue__2015.doc
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\issi2013_template_for_posters.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\adhd_and_obesity.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dialmap.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\holycrosschurchinstructions.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\api-hashmap.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\alert.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\tree_view.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\browse.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\about.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\pushkin.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\parnas_01.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\3.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\region-north-karelia.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\13.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\parnas_01.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\1189.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\pushkin.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\3.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\spib_pima.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2015-02-worms-nanoparticle-toxicity.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\ff_ot_user_guide.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dissolveanother.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\cbz.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\block.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\cleanlyrics.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\proposaltemplates.ppt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\sacs_presentation_sacs_qep_improving_rt_education_final.ppt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\middaugh_keynote.pptx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\waterresourcesag.pptx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\static_electricity_easy_and_quick_activities.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\waterlandhealthkano.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\router_manual.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\subjectclassification.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\contractualdeadlines.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\guide_reorganization_mapping.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\removedtitles_records.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\productos.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\fiche_inscription_2015.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\calculatorworksheet.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\price030215.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2013_finalsummaryforweb.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\trtf_matrix2012_oct.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\national_autism_preparation_programs.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\suspendedcompanies.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\highly_cited_2001.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber_xzaovwzjdun_20251016_161720.zip
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\chromium_cookies_xzaovwzjdun_2025-10-16_16.16.51.json
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\filezilla_xzaovwzjdun_2025-10-16_16.16.53.txt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\gecko_cookies_xzaovwzjdun_2025-10-16_16.16.53.json
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\aoc_saq_d_v3_merchant.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dashborder_96.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\default.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dial.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\dialmap.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\file_p_00000000_1371597592.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-c\users\user\desktop\issi2013_template_for_posters.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\1189.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\13.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2013_finalsummaryforweb.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\2015-02-worms-nanoparticle-toxicity.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\3.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\3.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\about.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\adhd_and_obesity.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\alert.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\api-hashmap.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\block.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\browse.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\calculatorworksheet.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\cbz.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\cleanlyrics.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\coffee.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\contractualdeadlines.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dashborder_120.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dashborder_96.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\default.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dial.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dialmap.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\dissolveanother.png
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\february_catalogue__2015.doc
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\ff_ot_user_guide.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\fiche_inscription_2015.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\guide_reorganization_mapping.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\highly_cited_2001.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\holycrosschurchinstructions.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\issi2013_template_for_posters.docx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\middaugh_keynote.pptx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\national_autism_preparation_programs.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\parnas_01.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\parnas_01.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\price030215.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\productos.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\proposaltemplates.ppt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\pushkin.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\pushkin.jpg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\region-north-karelia.jpeg
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\removedtitles_records.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\router_manual.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\sacs_presentation_sacs_qep_improving_rt_education_final.ppt
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\spib_pima.pdf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\static_electricity_easy_and_quick_activities.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\subjectclassification.xls
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\suspendedcompanies.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\tileimage.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\toolbar.bmp
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\tree_view.html
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\trtf_matrix2012_oct.xlsx
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\waterlandhealthkano.rtf
- %TEMP%\62a2c1d909872ee4bd10abf08b2e99a3\grabber\drive-f\waterresourcesag.pptx
- 'ap#.##legram.org':443
- 'ic###azip.com':80
- 'ft#.##traatech.com':21
- 'ap#.##legram.org':443
- 'ft#.##traatech.com':21
- DNS ASK ap#.##legram.org
- DNS ASK ic###azip.com
- DNS ASK ft#.##traatech.com