Technical Information
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %HOMEPATH%\desktop\lisp_success.doc
- %HOMEPATH%\desktop\ovp25012015.doc
- %HOMEPATH%\desktop\sdszfo.docx
- %TEMP%\vbs.vbs
- %LOCALAPPDATA%\m2ce1gj5\telegram\d877f783d5d3ef8c1
- %LOCALAPPDATA%\m2ce1gj5\discord\data.txt
- %LOCALAPPDATA%\m2ce1gj5\pidgin\data.txt
- %LOCALAPPDATA%\m2ce1gj5\filezilla\data.txt
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\sdszfo.docx
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\ovp25012015.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\lisp_success.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\hanni_umami_chapter.doc
- %LOCALAPPDATA%\m2ce1gj5\telegram\d877f783d5d3ef8c\map0
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\fi51.doc
- %LOCALAPPDATA%\m2ce1gj5\screenshot.png
- %LOCALAPPDATA%\m2ce1gj5\copyboard.txt
- %LOCALAPPDATA%\m2ce1gj5\processlist.txt
- %LOCALAPPDATA%\m2ce1gj5\system.txt
- %TEMP%\pl2d4vfegvbqddddkms0zhqii0i
- %TEMP%\hoonings.exe
- %TEMP%\hoonings.sfx.exe
- %TEMP%\bat.bat
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\508softwareandos.doc
- %LOCALAPPDATA%\m2ce1gj5\skype\data.txt
- %LOCALAPPDATA%\m2ce1gj5\copyboard.txt
- %LOCALAPPDATA%\m2ce1gj5\discord\data.txt
- %LOCALAPPDATA%\m2ce1gj5\filezilla\data.txt
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\508softwareandos.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\fi51.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\hanni_umami_chapter.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\lisp_success.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\ovp25012015.doc
- %LOCALAPPDATA%\m2ce1gj5\grabber\desktop files\sdszfo.docx
- %LOCALAPPDATA%\m2ce1gj5\pidgin\data.txt
- %LOCALAPPDATA%\m2ce1gj5\processlist.txt
- %LOCALAPPDATA%\m2ce1gj5\screenshot.png
- %LOCALAPPDATA%\m2ce1gj5\skype\data.txt
- %LOCALAPPDATA%\m2ce1gj5\system.txt
- %LOCALAPPDATA%\m2ce1gj5\telegram\d877f783d5d3ef8c\map0
- %LOCALAPPDATA%\m2ce1gj5\telegram\d877f783d5d3ef8c1
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\vbs.vbs"
- '%TEMP%\hoonings.sfx.exe' -phoonings.exe -d%LOCALAPPDATA%\Temp
- '%TEMP%\hoonings.exe'
- '%WINDIR%\syswow64\cmd.exe' /c bat.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c bat.bat