Technical Information
- <SYSTEM32>\tasks\updates\eehsgibiq
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %APPDATA%\eehsgibiq.exe
- %TEMP%\tmpfb1a.tmp
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %TEMP%\62fe212ac3\log.txt
- %TEMP%\62fe212ac3\screenshot.jpeg
- %TEMP%\62fe212ac3\dotnetzip-cm3q5t0j.tmp
- from %TEMP%\62fe212ac3\dotnetzip-cm3q5t0j.tmp to %TEMP%\62fe212ac3\user_united states_62fe212ac3_09-15-2025 8.5.50.zip
- 'ap#.#pify.org':80
- 'ma##.##ivateemail.com':587
- http://ap#.#pify.org/
- 'ma##.##ivateemail.com':587
- DNS ASK ap#.#pify.org
- DNS ASK ma##.##ivateemail.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\EeHSGIbIq" /XML "%TEMP%\tmpFB1A.tmp"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\EeHSGIbIq" /XML "%TEMP%\tmpFB1A.tmp"' (with hidden window)