Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- C:\portfontdriverref\comcontaineragentserver.exe
- %TEMP%\gbyqnelmw0
- %TEMP%\lusmvq0fmj
- %TEMP%\svcl6ux8wj
- %TEMP%\pj9czxozct
- %TEMP%\elpmnmchuy
- %TEMP%\p95ju0b4x3
- %TEMP%\vckamdcdkb
- %TEMP%\wkynktqzea
- %TEMP%\dmw1yvbmxl
- %HOMEPATH%\desktop\qtsbymbz.log
- %HOMEPATH%\desktop\yxbrifrh.log
- %HOMEPATH%\desktop\spxmjfho.log
- %HOMEPATH%\desktop\yeveuhit.log
- C:\portfontdriverref\uwjaidpptquptkm72u8tjtlzojay.bat
- C:\portfontdriverref\nhjhhelul1tlczciddejmy041cb20bpksu5xnsuz2xyn0bewrs9ybvss.vbe
- %TEMP%\xmobgu674m
- %TEMP%\xvmg541xqj
- %TEMP%\dmw1yvbmxl
- '81#####m.n9shteam3.top':80
- http://81#####m.n9shteam3.top/ImagePipeLowAuthgameflowertestprivate.php
- DNS ASK 81#####m.n9shteam3.top
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\portfontDriverRef\nhjhHElUL1tLCzCIDDeJMy041CB20BPkSu5XNsuz2xyN0BEWrS9YbVss.vbe"
- 'C:\portfontdriverref\comcontaineragentserver.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\portfontDriverRef\UWjaidppTQUpTkM72U8TJTLZoJay.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\portfontDriverRef\UWjaidppTQUpTkM72U8TJTLZoJay.bat" "' (with hidden window)