Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\system.lnk
- C:\data\loader.exe
- %TEMP%\_mei20602\win32file.pyd
- %TEMP%\_mei20602\win32event.pyd
- %TEMP%\_mei20602\win32com\shell\shell.pyd
- %TEMP%\_mei20602\win32api.pyd
- %TEMP%\_mei20602\unicodedata.pyd
- %TEMP%\_mei20602\ucrtbase.dll
- %TEMP%\_mei20602\select.pyd
- %TEMP%\_mei20602\pywin32_system32\pywintypes311.dll
- %TEMP%\_mei20602\pywin32_system32\pythoncom311.dll
- %TEMP%\_mei20602\python311.dll
- %TEMP%\_mei20602\python3.dll
- %TEMP%\_mei20602\win32pipe.pyd
- %TEMP%\_mei20602\win32gui.pyd
- %TEMP%\_mei20602\markupsafe\_speedups.cp311-win_amd64.pyd
- %TEMP%\_mei20602\libssl-1_1.dll
- %TEMP%\_mei20602\libffi-8.dll
- %TEMP%\_mei20602\libcrypto-1_1.dll
- %TEMP%\_mei20602\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei20602\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei20602\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei20602\pyexpat.pyd
- %TEMP%\_mei20602\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei20602\win32process.pyd
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\wheel
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\record
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\metadata
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\license.txt
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\installer
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\top_level.txt
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\entry_points.txt
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\wheel
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\record
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\metadata
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\license
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\installer
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\top_level.txt
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\wheel
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\record
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\metadata
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.psf
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.bsd
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.apache
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\installer
- %TEMP%\_mei20602\base_library.zip
- %TEMP%\_mei20602\zope\interface\_zope_interface_coptimizations.cp311-win_amd64.pyd
- %TEMP%\_mei20602\win32ui.pyd
- %TEMP%\_mei20602\win32trace.pyd
- %TEMP%\_mei20602\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei20602\mfc140u.dll
- %TEMP%\_mei20602\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei20602\_cffi_backend.cp311-win_amd64.pyd
- %TEMP%\_mei20602\_win32sysloader.pyd
- %TEMP%\_mei20602\_uuid.pyd
- %TEMP%\_mei20602\_ssl.pyd
- %TEMP%\_mei20602\_socket.pyd
- %TEMP%\_mei20602\_queue.pyd
- %TEMP%\_mei20602\_overlapped.pyd
- %TEMP%\_mei20602\_multiprocessing.pyd
- %TEMP%\_mei20602\_lzma.pyd
- %TEMP%\_mei20602\_hashlib.pyd
- %TEMP%\_mei20602\_decimal.pyd
- %TEMP%\_mei20602\_ctypes.pyd
- %TEMP%\_mei20602\_bz2.pyd
- %TEMP%\_mei20602\api-ms-win-core-datetime-l1-1-0.dll
- nul
- %TEMP%\_mei20602\_asyncio.pyd
- %TEMP%\_mei20602\vcruntime140.dll
- C:\data\system.vbs
- C:\data\audio.vbs
- C:\data\verus-solver.exe
- C:\data\hellminer.exe
- C:\data\uninstall.cmd
- C:\data\system.bat
- %APPDATA%\winrar\version.dat
- C:\data\cs2.zip
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\entry_points.txt
- %TEMP%\_mei20602\win32security.pyd
- %TEMP%\_mei20602\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei20602\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\top_level.txt
- %TEMP%\_mei20602\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\record
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\metadata
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\license.txt
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\installer
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\entry_points.txt
- %TEMP%\_mei20602\vcruntime140.dll
- %TEMP%\_mei20602\unicodedata.pyd
- %TEMP%\_mei20602\ucrtbase.dll
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\wheel
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\top_level.txt
- %TEMP%\_mei20602\libssl-1_1.dll
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\record
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\license
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\installer
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\entry_points.txt
- %TEMP%\_mei20602\select.pyd
- %TEMP%\_mei20602\pywin32_system32\pywintypes311.dll
- %TEMP%\_mei20602\pywin32_system32\pythoncom311.dll
- %TEMP%\_mei20602\python311.dll
- %TEMP%\_mei20602\python3.dll
- %TEMP%\_mei20602\pyexpat.pyd
- %TEMP%\_mei20602\mfc140u.dll
- %TEMP%\_mei20602\setuptools-65.5.0.dist-info\metadata
- %TEMP%\_mei20602\markupsafe\_speedups.cp311-win_amd64.pyd
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\top_level.txt
- %TEMP%\_mei20602\_asyncio.pyd
- %TEMP%\_mei20602\_ssl.pyd
- %TEMP%\_mei20602\_socket.pyd
- %TEMP%\_mei20602\_queue.pyd
- %TEMP%\_mei20602\_overlapped.pyd
- %TEMP%\_mei20602\_multiprocessing.pyd
- %TEMP%\_mei20602\_lzma.pyd
- %TEMP%\_mei20602\_hashlib.pyd
- %TEMP%\_mei20602\_decimal.pyd
- %TEMP%\_mei20602\_ctypes.pyd
- %TEMP%\_mei20602\_cffi_backend.cp311-win_amd64.pyd
- %TEMP%\_mei20602\win32api.pyd
- %TEMP%\_mei20602\wheel-0.38.4.dist-info\wheel
- %TEMP%\_mei20602\zope\interface\_zope_interface_coptimizations.cp311-win_amd64.pyd
- %TEMP%\_mei20602\win32ui.pyd
- %TEMP%\_mei20602\win32trace.pyd
- %TEMP%\_mei20602\win32security.pyd
- %TEMP%\_mei20602\win32process.pyd
- %TEMP%\_mei20602\win32pipe.pyd
- %TEMP%\_mei20602\win32gui.pyd
- %TEMP%\_mei20602\win32file.pyd
- %TEMP%\_mei20602\win32event.pyd
- %TEMP%\_mei20602\win32com\shell\shell.pyd
- %TEMP%\_mei20602\_bz2.pyd
- %TEMP%\_mei20602\libffi-8.dll
- %TEMP%\_mei20602\libcrypto-1_1.dll
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\wheel
- %TEMP%\_mei20602\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei20602\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei20602\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\top_level.txt
- %TEMP%\_mei20602\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\record
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\metadata
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.psf
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.bsd
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license.apache
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\license
- %TEMP%\_mei20602\cryptography-39.0.0.dist-info\installer
- %TEMP%\_mei20602\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei20602\cryptography\hazmat\bindings\_openssl.pyd
- %TEMP%\_mei20602\base_library.zip
- %TEMP%\_mei20602\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei20602\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei20602\_uuid.pyd
- %TEMP%\_mei20602\_win32sysloader.pyd
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'WinRarWindow' WindowName: ''
- 'C:\data\loader.exe'
- '<SYSTEM32>\wscript.exe' "C:\data\audio.vbs"
- '<SYSTEM32>\wscript.exe' "C:\data\system.vbs"
- 'C:\data\hellminer.exe' -c stratum+tcp://na.luckpool.net:3960 -u RGPwLAwTLQqjJjs6AiHGJYHHfF6tD4UHVg.node1 -p x --threads=1
- '%ProgramFiles%\winrar\winrar.exe' "C:\data\cs2.zip"
- '<SYSTEM32>\cmd.exe' /k system.bat
- '<SYSTEM32>\cmd.exe' /c wmic cpu get numberofcores|findstr "^[0-9]"
- '<SYSTEM32>\findstr.exe' "^[0-9]"
- '<SYSTEM32>\wbem\wmic.exe' cpu get numberofcores
- '<SYSTEM32>\ping.exe' -n 2 localhost
- '<SYSTEM32>\cmd.exe' /c tasklist /NH /FI "imagename eq taskmgr.exe"
- '<SYSTEM32>\tasklist.exe' /NH /FI "imagename eq taskmgr.exe"
- '<SYSTEM32>\cmd.exe' /k system.bat' (with hidden window)