Technical Information
- <SYSTEM32>\tasks\runtimebroker
- %TEMP%\_mei40642\vcruntime140.dll
- %TEMP%\_mei40642\_bz2.pyd
- %TEMP%\_mei40642\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei40642\_decimal.pyd
- %TEMP%\_mei40642\_hashlib.pyd
- %TEMP%\_mei40642\_lzma.pyd
- %TEMP%\_mei40642\_socket.pyd
- %TEMP%\_mei40642\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei40642\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei40642\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei40642\base_library.zip
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\installer
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.apache
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.bsd
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.psf
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\metadata
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\record
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\wheel
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\top_level.txt
- %TEMP%\_mei40642\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei40642\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei40642\libcrypto-1_1.dll
- %TEMP%\_mei40642\python3.dll
- %TEMP%\_mei40642\python310.dll
- %TEMP%\_mei40642\select.pyd
- %TEMP%\_mei40642\temp_wrapper.exe.manifest
- %TEMP%\_mei40642\ucrtbase.dll
- %TEMP%\_mei40642\unicodedata.pyd
- %TEMP%\_mei40642\junkb7757a254f4b
- %TEMP%\_mei40642\junk3438caa2fd0f
- %TEMP%\_mei40642\junkaf2625dcd5de
- %TEMP%\_mei40642\tmp_207f2002_temp_wrapper.py
- %ProgramFiles(x86)%\internet explorer\runtimebroker.exe
- %ProgramFiles(x86)%\microsoft\edge\application\runtimebroker.exe
- nul
- %ProgramFiles(x86)%\internet explorer\runtimebroker.exe
- %TEMP%\_mei40642\junk3438caa2fd0f
- %TEMP%\_mei40642\junkaf2625dcd5de
- %TEMP%\_mei40642\junkb7757a254f4b
- %TEMP%\_mei40642\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei40642\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei40642\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei40642\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei40642\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei40642\base_library.zip
- %TEMP%\_mei40642\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei40642\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\installer
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.apache
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.bsd
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\license.psf
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\metadata
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\record
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\top_level.txt
- %TEMP%\_mei40642\cryptography-36.0.1.dist-info\wheel
- %TEMP%\_mei40642\libcrypto-1_1.dll
- %TEMP%\_mei40642\python3.dll
- %TEMP%\_mei40642\python310.dll
- %TEMP%\_mei40642\select.pyd
- %TEMP%\_mei40642\temp_wrapper.exe.manifest
- %TEMP%\_mei40642\temp_wrapper.py
- %TEMP%\_mei40642\ucrtbase.dll
- %TEMP%\_mei40642\unicodedata.pyd
- %TEMP%\_mei40642\vcruntime140.dll
- %TEMP%\_mei40642\_bz2.pyd
- %TEMP%\_mei40642\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei40642\_decimal.pyd
- %TEMP%\_mei40642\_hashlib.pyd
- %TEMP%\_mei40642\_lzma.pyd
- %TEMP%\_mei40642\_socket.pyd
- %ProgramFiles(x86)%\microsoft\edge\application\runtimebroker.exe
- from %TEMP%\_mei40642\tmp_207f2002_temp_wrapper.py to %TEMP%\_mei40642\temp_wrapper.py
- 'gi##ab.com':443
- 'gi##ab.com':443
- DNS ASK dn#.google
- DNS ASK gi##ab.com
- 'dn#.google':443
- '18#.#14.96.1':443
- '%TEMP%\_mei40642\temp_wrapper.py'
- '%ProgramFiles(x86)%\internet explorer\runtimebroker.exe'
- '%ProgramFiles(x86)%\microsoft\edge\application\runtimebroker.exe' -
- '<SYSTEM32>\cmd.exe' /c "ver"
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\_MEI40642\temp_wrapper.py"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe'
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s UmRdpService
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\_MEI40642\temp_wrapper.py"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' ' (with hidden window)
- '%ProgramFiles(x86)%\microsoft\edge\application\runtimebroker.exe' -' (with hidden window)