Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\login data
 - %LOCALAPPDATA%\microsoft\edge\user data\default\login data
 - %LOCALAPPDATA%\google\chrome\user data\default\cookies
 
- %TEMP%\_mei21122\vcruntime140.dll
 - %TEMP%\_mei21122\_bz2.pyd
 - %TEMP%\_mei21122\_decimal.pyd
 - %TEMP%\_mei21122\_hashlib.pyd
 - %TEMP%\_mei21122\_lzma.pyd
 - %TEMP%\_mei21122\_socket.pyd
 - %TEMP%\_mei21122\base_library.zip
 - %TEMP%\_mei21122\libcrypto-1_1.dll
 - %TEMP%\_mei21122\python310.dll
 - %TEMP%\_mei21122\select.pyd
 - %TEMP%\_mei21122\unicodedata.pyd
 - %TEMP%\ekwv9a2s
 - %TEMP%\winstore.app.exe
 - %TEMP%\_mei11082\vcruntime140.dll
 - %TEMP%\_mei11082\_asyncio.pyd
 - %TEMP%\_mei11082\_bz2.pyd
 - %TEMP%\_mei11082\_cffi_backend.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\_ctypes.pyd
 - %TEMP%\_mei11082\_decimal.pyd
 - %TEMP%\_mei11082\_hashlib.pyd
 - %TEMP%\_mei11082\_lzma.pyd
 - %TEMP%\_mei11082\_multiprocessing.pyd
 - %TEMP%\_mei11082\_overlapped.pyd
 - %TEMP%\_mei11082\_queue.pyd
 - %TEMP%\_mei11082\_socket.pyd
 - %TEMP%\_mei11082\_sqlite3.pyd
 - %TEMP%\_mei11082\_ssl.pyd
 - %TEMP%\_mei11082\base_library.zip
 - %TEMP%\_mei11082\certifi\cacert.pem
 - %TEMP%\_mei11082\charset_normalizer\md.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\installer
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\metadata
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\record
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\wheel
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.apache
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.bsd
 - %TEMP%\_mei11082\cryptography\hazmat\bindings\_rust.pyd
 - %TEMP%\_mei11082\libcrypto-1_1.dll
 - %TEMP%\_mei11082\libffi-7.dll
 - %TEMP%\_mei11082\libssl-1_1.dll
 - %TEMP%\_mei11082\pyexpat.pyd
 - %TEMP%\_mei11082\python3.dll
 - %TEMP%\_mei11082\python310.dll
 - %TEMP%\_mei11082\select.pyd
 - %TEMP%\_mei11082\sqlite3.dll
 - %TEMP%\_mei11082\unicodedata.pyd
 - %TEMP%\age8jm0d
 - nul
 - %TEMP%\microsoft_vc_redist\system_info.txt
 - %TEMP%\microsoft_vc_redist\discord_tokens.txt
 - %TEMP%\microsoft_vc_redist\chrome_logins_temp.db
 - %TEMP%\microsoft_vc_redist\edge_logins_temp.db
 - %TEMP%\microsoft_vc_redist\all_browser_logins.json
 - %TEMP%\microsoft_vc_redist\browser_logins_readable.txt
 - %TEMP%\microsoft_vc_redist\chrome_cookies_temp.db
 - %TEMP%\microsoft_vc_redist\all_browser_cookies.json
 - %TEMP%\microsoft_vc_redist\chrome_history_temp.db
 - %TEMP%\microsoft_vc_redist\edge_history_temp.db
 - %TEMP%\microsoft_vc_redist\all_browser_history.json
 - %TEMP%\microsoft_vc_redist\firefox_history_temp.db
 - %TEMP%\microsoft_vc_redist\firefox_history_temp.db-shm
 - %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db
 - %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db-shm
 - %TEMP%\microsoft_vc_redist\firefox_data.json
 - %TEMP%\microsoft_vc_redist\browser_data_summary.txt
 - %TEMP%\microsoft_vc_redist\decrypted_browser_data.json
 - %TEMP%\microsoft_vc_redist\network_info.txt
 - %TEMP%\vc_redist_part_1.zip
 
- %TEMP%\ekwv9a2s
 - %TEMP%\_mei21122\base_library.zip
 - %TEMP%\_mei21122\libcrypto-1_1.dll
 - %TEMP%\_mei21122\python310.dll
 - %TEMP%\_mei21122\select.pyd
 - %TEMP%\_mei21122\unicodedata.pyd
 - %TEMP%\_mei21122\vcruntime140.dll
 - %TEMP%\_mei21122\_bz2.pyd
 - %TEMP%\_mei21122\_decimal.pyd
 - %TEMP%\_mei21122\_hashlib.pyd
 - %TEMP%\_mei21122\_lzma.pyd
 - %TEMP%\_mei21122\_socket.pyd
 - %TEMP%\age8jm0d
 - %TEMP%\microsoft_vc_redist\chrome_logins_temp.db
 - %TEMP%\microsoft_vc_redist\edge_logins_temp.db
 - %TEMP%\microsoft_vc_redist\chrome_cookies_temp.db
 - %TEMP%\microsoft_vc_redist\chrome_history_temp.db
 - %TEMP%\microsoft_vc_redist\edge_history_temp.db
 - %TEMP%\microsoft_vc_redist\firefox_history_temp.db-shm
 - %TEMP%\microsoft_vc_redist\firefox_history_temp.db
 - %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db-shm
 - %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db
 - %TEMP%\microsoft_vc_redist\all_browser_cookies.json
 - %TEMP%\microsoft_vc_redist\all_browser_history.json
 - %TEMP%\microsoft_vc_redist\all_browser_logins.json
 - %TEMP%\microsoft_vc_redist\browser_data_summary.txt
 - %TEMP%\microsoft_vc_redist\browser_logins_readable.txt
 - %TEMP%\microsoft_vc_redist\decrypted_browser_data.json
 - %TEMP%\microsoft_vc_redist\discord_tokens.txt
 - %TEMP%\microsoft_vc_redist\firefox_data.json
 - %TEMP%\microsoft_vc_redist\network_info.txt
 - %TEMP%\microsoft_vc_redist\system_info.txt
 - %TEMP%\vc_redist_part_1.zip
 - %TEMP%\_mei11082\base_library.zip
 - %TEMP%\_mei11082\certifi\cacert.pem
 - %TEMP%\_mei11082\charset_normalizer\md.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\cryptography\hazmat\bindings\_rust.pyd
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\installer
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.apache
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.bsd
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\metadata
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\record
 - %TEMP%\_mei11082\cryptography-46.0.3.dist-info\wheel
 - %TEMP%\_mei11082\libcrypto-1_1.dll
 - %TEMP%\_mei11082\libffi-7.dll
 - %TEMP%\_mei11082\libssl-1_1.dll
 - %TEMP%\_mei11082\pyexpat.pyd
 - %TEMP%\_mei11082\python3.dll
 - %TEMP%\_mei11082\python310.dll
 - %TEMP%\_mei11082\select.pyd
 - %TEMP%\_mei11082\sqlite3.dll
 - %TEMP%\_mei11082\unicodedata.pyd
 - %TEMP%\_mei11082\vcruntime140.dll
 - %TEMP%\_mei11082\_asyncio.pyd
 - %TEMP%\_mei11082\_bz2.pyd
 - %TEMP%\_mei11082\_cffi_backend.cp310-win_amd64.pyd
 - %TEMP%\_mei11082\_ctypes.pyd
 - %TEMP%\_mei11082\_decimal.pyd
 - %TEMP%\_mei11082\_hashlib.pyd
 - %TEMP%\_mei11082\_lzma.pyd
 - %TEMP%\_mei11082\_multiprocessing.pyd
 - %TEMP%\_mei11082\_overlapped.pyd
 - %TEMP%\_mei11082\_queue.pyd
 - %TEMP%\_mei11082\_socket.pyd
 - %TEMP%\_mei11082\_sqlite3.pyd
 - %TEMP%\_mei11082\_ssl.pyd
 
- 'ap#.#pify.org':443
 - 'di##ord.com':443
 
- 'ap#.#pify.org':443
 - 'di##ord.com':443
 
- DNS ASK ap#.#pify.org
 - DNS ASK di##ord.com
 
- '%TEMP%\winstore.app.exe'
 
- '<SYSTEM32>\cmd.exe' /c "ver"
 - '<SYSTEM32>\netsh.exe' wlan show profiles
 - '%TEMP%\winstore.app.exe' ' (with hidden window)
 - '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)