Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\warsawsecurity.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\myapp.lnk
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- <Current directory>\extension\0_manifest.json
- <Current directory>\extension\1_manifest.json
- <Current directory>\extension\2_manifest.json
- <Current directory>\extension\3_manifest.json
- <Current directory>\extension\4_manifest.json
- <Current directory>\history
- <Current directory>\download
- <Current directory>\password
- <Current directory>\creditcard
- <Current directory>\chromiumkey
- <Current directory>\cookie
- <Current directory>\chromiumkey
- '13#.#85.238.251':7777
- '<SYSTEM32>\cmd.exe' ver
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive "$WshShell = New-Object -comObject WScript.Shell $Shortcut = $WshShell.CreateShortcut(\"$HOME\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyAPP.lnk\...
- '<SYSTEM32>\cmd.exe' ver' (with hidden window)