Technical Information
- <SYSTEM32>\tasks\updates\rfmjliouhklt
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %APPDATA%\rfmjliouhklt.exe
- %TEMP%\tmp3bf1.tmp
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %TEMP%\7777b6c05c\log.txt
- %TEMP%\7777b6c05c\screenshot.jpeg
- %TEMP%\7777b6c05c\dotnetzip-aesrumib.tmp
- from %TEMP%\7777b6c05c\dotnetzip-aesrumib.tmp to %TEMP%\7777b6c05c\user_united states_7777b6c05c_09-15-2025 9.2.16.zip
- 'ap#.#pify.org':80
- 'ma##.##ivateemail.com':587
- http://ap#.#pify.org/
- 'ma##.##ivateemail.com':587
- DNS ASK ap#.#pify.org
- DNS ASK ma##.##ivateemail.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\rFmjLiOuHKlT" /XML "%TEMP%\tmp3BF1.tmp"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\rFmjLiOuHKlT" /XML "%TEMP%\tmp3BF1.tmp"' (with hidden window)