Technical Information
- [HKCU\Software\Far\Plugins\FTP\Hosts]
- [HKCU\Software\Far2\Plugins\FTP\Hosts]
- [HKCU\Software\Google\Google Talk\Accounts]
- [HKLM\SOFTWARE\Wow6432Node\FlashFXP]
- [HKLM\Software\Wow6432Node\Ghisler\Total Commander]
- [HKCU\Software\Ghisler\Total Commander]
- ClassName: 'PROCEXPL', WindowName: ''
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: 'gdkWindowToplevel', WindowName: 'The Wireshark Network Analyzer'
- %TEMP%\<File name>.exe
- %TEMP%\report_12-05-2023_15-22-56-gaia.bin
- %TEMP%\ufr_files\report_12-05-2023_15-22-56-gaia.bin
- %TEMP%\<File name>.exe
- %TEMP%\report_12-05-2023_15-22-56-gaia.bin
- DNS ASK sm##.mail.ru
- '%TEMP%\<File name>.exe'