Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe
- firefox.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %TEMP%\runtime.msil.1.0.0.0\nativepro.dll
- %ALLUSERSPROFILE%\6171
- %ALLUSERSPROFILE%\61\softokn3.dll
- %ALLUSERSPROFILE%\61\sqlite3.dll
- %ALLUSERSPROFILE%\61\vcruntime140.dll
- %ALLUSERSPROFILE%\61\freebl3.dll
- %ALLUSERSPROFILE%\61\mozglue.dll
- %ALLUSERSPROFILE%\61\msvcp140.dll
- %ALLUSERSPROFILE%\61\nss3.dll
- %ALLUSERSPROFILE%\61\39891d4e72d5229a364eeb04022f0eb3.txt
- %ALLUSERSPROFILE%\61\7031d009f15bb0518b6151e8344712de.txt
- %ALLUSERSPROFILE%\61\62f633130103d3b85c0e04cd9adc9369.txt
- %ALLUSERSPROFILE%\61\26306aae81e784e6d79b2e86375d8638.txt
- %ALLUSERSPROFILE%\61\85eff8221e46df4572afa364e6c34e2e.txt
- %ALLUSERSPROFILE%\61\96387ddbf8c39f7318b14e0aeb2e9238.txt
- %ALLUSERSPROFILE%\61\26306aae81e784e6d79b2e86375d8638.txt
- %ALLUSERSPROFILE%\61\39891d4e72d5229a364eeb04022f0eb3.txt
- %ALLUSERSPROFILE%\61\62f633130103d3b85c0e04cd9adc9369.txt
- %ALLUSERSPROFILE%\61\7031d009f15bb0518b6151e8344712de.txt
- %ALLUSERSPROFILE%\61\85eff8221e46df4572afa364e6c34e2e.txt
- %ALLUSERSPROFILE%\61\96387ddbf8c39f7318b14e0aeb2e9238.txt
- %ALLUSERSPROFILE%\61\freebl3.dll
- %ALLUSERSPROFILE%\61\mozglue.dll
- %ALLUSERSPROFILE%\61\msvcp140.dll
- %ALLUSERSPROFILE%\61\nss3.dll
- %ALLUSERSPROFILE%\61\softokn3.dll
- %ALLUSERSPROFILE%\61\sqlite3.dll
- %ALLUSERSPROFILE%\61\vcruntime140.dll
- %ALLUSERSPROFILE%\6171
- http://p4##ls.xyz/?id####
- http://sh###-912.xyz/api.php
- http://sh###-912.xyz/api.php?ge######
- DNS ASK p4##ls.xyz
- DNS ASK sh###-912.xyz
- '%WINDIR%\microsoft.net\framework\v4.0.30319\addinprocess32.exe'