Technical Information
- '%TEMP%\ccecabfgac.exe' 6-6-4-9-1-0-3-2-5-1-7 KUpFOzwzLy4rHyhNTz5HSEQ6LhsuRz9OU0ZRS0ZCOC8ZKT5FSlNJQTstMS4uGis6SEQ6LhsuSUxJQExCVFxHPzwqKi0uFy5TQlBRREtZT05DPGhxcms5KCltYWl1LnFmYCxaamopW2B0XixkbV9pGis6S0lASURDNhopQCg8MSIwXiwqGilAKTwtLh4qQyw3Jy0XLkQxOygwGSk+MTQsMR0tS1FIPk8/S15QT0dRQDxTNxwmT1JMQlBCTVk/UUNAPR0tS1FIPk8/S15OPktAPBkpP1Q8XlVPSjgfKD9SQVZCTUFKRE0+NxorP05TUV09UUhRTUFJPDIdLU9HOkhFVUZUX1JQRzwZKVBJNDEgLEJOMDYaKU5MTVRGS0BeUD9GP0ZMRUZLPEY+T0xINB8vRlFaUU5ITkVERD1xcHBkGSlMQUtUUktHSUZYT01BSV5EPldOPCsaKURAQ0VVOywfKENNWztYTj5LREJYP0g/SVhQUUM/PF9bZm9cHy9BTVJNRUk7QFZIUDowLy0rLiguKDUuLjUrHyhOQ0k8PDExMC82MiwrLCkfL0FNUk1FSTtAVlNJSkM4MSgsLispLzEyKC45LC80LCkpUEo=
- '%TEMP%\videoplayer-setup.exe'
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431814280.txt bios get version
- '<SYSTEM32>\wbem\wmic.exe' /output:%TEMP%\81431814280.txt bios get serialnumber
- %TEMP%\nsl10.tmp\nsisunz.dll
- %TEMP%\rc27.exe
- %TEMP%\ccecabfgac.zip
- %TEMP%\rc27.ccecabfgac
- %TEMP%\nsl10.tmp\rtm.dll
- %TEMP%\tmp11.tmp
- <SYSTEM32>\wbem\AutoRecover\23BDE61F1F4FACE17E9B0C01F2A1FD9B.mof
- %TEMP%\81431814280.txt
- %TEMP%\tmp13.tmp
- %TEMP%\tmp12.tmp
- <SYSTEM32>\wbem\AutoRecover\C8463ECBE33BC240263A0B094E46D510.mof
- %TEMP%\vu5z11bv.x0m
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
- %TEMP%\Cab1.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
- %TEMP%\Cab3.tmp
- %TEMP%\CabB.tmp
- %TEMP%\CabD.tmp
- %TEMP%\Cab9.tmp
- %TEMP%\Cab5.tmp
- %TEMP%\Cab7.tmp
- %TEMP%\tmp11.tmp
- %TEMP%\CabD.tmp
- %TEMP%\tmp12.tmp
- %TEMP%\81431814280.txt
- %TEMP%\tmp13.tmp
- %TEMP%\CabB.tmp
- %TEMP%\Cab3.tmp
- %TEMP%\Cab1.tmp
- %TEMP%\Cab5.tmp
- %TEMP%\Cab9.tmp
- %TEMP%\Cab7.tmp
- from %TEMP%\rc27.exe to %TEMP%\ccecabfgac.exe
- from %TEMP%\vu5z11bv.x0m to %TEMP%\videoplayer-setup.exe
- 'tl.##mcb.com':80
- 'www.download.windowsupdate.com':80
- 'wp#d':80
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- http://tl.##mcb.com/tl.crt
- http://11#.#11.111.1/wpad.dat via wp#d
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- DNS ASK tl.##mcb.com
- DNS ASK www.download.windowsupdate.com
- DNS ASK wp#d