Technical Information
- <SYSTEM32>\tasks\updates\uqfvqh
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %APPDATA%\uqfvqh.exe
- %TEMP%\tmp9362.tmp
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %TEMP%\3f0fe294b5\log.txt
- %TEMP%\3f0fe294b5\screenshot.jpeg
- %TEMP%\3f0fe294b5\dotnetzip-wvpksghn.tmp
- from %TEMP%\3f0fe294b5\dotnetzip-wvpksghn.tmp to %TEMP%\3f0fe294b5\user_united states_3f0fe294b5_09-15-2025 8.42.14.zip
- 'ap#.#pify.org':80
- 'ma##.##ivateemail.com':587
- http://ap#.#pify.org/
- 'ma##.##ivateemail.com':587
- DNS ASK ap#.#pify.org
- DNS ASK ma##.##ivateemail.com
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\uQFVQh" /XML "%TEMP%\tmp9362.tmp"
- '%WINDIR%\syswow64\schtasks.exe' /Create /TN "Updates\uQFVQh" /XML "%TEMP%\tmp9362.tmp"' (with hidden window)