Technical Information
- <SYSTEM32>\tasks\runtimebroker
- %TEMP%\_mei54202\vcruntime140.dll
- %TEMP%\_mei54202\_bz2.pyd
- %TEMP%\_mei54202\_cffi_backend.cp313-win_amd64.pyd
- %TEMP%\_mei54202\_decimal.pyd
- %TEMP%\_mei54202\_hashlib.pyd
- %TEMP%\_mei54202\_lzma.pyd
- %TEMP%\_mei54202\_socket.pyd
- %TEMP%\_mei54202\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei54202\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei54202\base_library.zip
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei54202\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei54202\libcrypto-3.dll
- %TEMP%\_mei54202\python3.dll
- %TEMP%\_mei54202\python313.dll
- %TEMP%\_mei54202\select.pyd
- %TEMP%\_mei54202\ucrtbase.dll
- %TEMP%\_mei54202\unicodedata.pyd
- %TEMP%\0ipwjt95
- %TEMP%\tmpnfz58qu5.exe
- %APPDATA%\.runtime\runtimebroker.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\tmpnfz58qu5.exe.log
- %TEMP%\z2gws3rq1dwa.bat
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\runtimebroker.exe.log
- nul
- %TEMP%\fp8pur64cbs8.bat
- %TEMP%\8bi4jrp7h4iy.bat
- %TEMP%\bj7lddtmixiz.bat
- %TEMP%\pinlh4hmtkwp.bat
- %TEMP%\wf9j1hdpnr37.bat
- %APPDATA%\.runtime\runtimebroker.exe
- %TEMP%\0ipwjt95
- %TEMP%\tmpnfz58qu5.exe
- %TEMP%\_mei54202\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei54202\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei54202\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei54202\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei54202\base_library.zip
- %TEMP%\_mei54202\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei54202\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei54202\libcrypto-3.dll
- %TEMP%\_mei54202\python3.dll
- %TEMP%\_mei54202\python313.dll
- %TEMP%\_mei54202\select.pyd
- %TEMP%\_mei54202\ucrtbase.dll
- %TEMP%\_mei54202\unicodedata.pyd
- %TEMP%\_mei54202\vcruntime140.dll
- %TEMP%\_mei54202\_bz2.pyd
- %TEMP%\_mei54202\_cffi_backend.cp313-win_amd64.pyd
- %TEMP%\_mei54202\_decimal.pyd
- %TEMP%\_mei54202\_hashlib.pyd
- %TEMP%\_mei54202\_lzma.pyd
- %TEMP%\_mei54202\_socket.pyd
- DNS ASK us######9-21690.portmap.io
- '%TEMP%\tmpnfz58qu5.exe'
- '%APPDATA%\.runtime\runtimebroker.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "RuntimeBroker" /sc ONLOGON /tr "%APPDATA%\.runtime\RuntimeBroker.exe" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Z2gwS3RQ1dwa.bat" "
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\ping.exe' -n 10 localhost
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\fP8puR64CBs8.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\8bi4jrP7H4IY.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\bj7lDdtMixIz.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\pInlh4hMtkwp.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\wf9J1hDPNR37.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\HpgxFQAt7G43.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\KSVo6JJdDK0o.bat" "
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\KyY7UmLi9CD9.bat" "
- '%TEMP%\tmpnfz58qu5.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\Z2gwS3RQ1dwa.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\fP8puR64CBs8.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\8bi4jrP7H4IY.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\bj7lDdtMixIz.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\pInlh4hMtkwp.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\wf9J1hDPNR37.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\HpgxFQAt7G43.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\KSVo6JJdDK0o.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\KyY7UmLi9CD9.bat" "' (with hidden window)