Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %TEMP%\451a.tmp
- %TEMP%\47e9.tmp
- %TEMP%\47e9.tmp-shm
- %TEMP%\49fc.tmp
- %TEMP%\49fc.tmp-shm
- %TEMP%\451a.tmp
- %TEMP%\47e9.tmp-shm
- %TEMP%\47e9.tmp
- %TEMP%\49fc.tmp-shm
- %TEMP%\49fc.tmp
- %TEMP%\451a.tmp
- %TEMP%\47e9.tmp
- %TEMP%\47e9.tmp-shm
- %TEMP%\49fc.tmp
- %TEMP%\49fc.tmp-shm
- '34.##9.100.209':443
- '34.##7.121.53':443
- DNS ASK mo####naoron.top
- '%WINDIR%\syswow64\cmd.exe' /c ping localhost -n 4 && del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ping localhost -n 4 && del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' localhost -n 4