Technical Information
- '<SYSTEM32>\taskkill.exe' /f /t /im firefox.exe
- '<SYSTEM32>\taskkill.exe' /IM Telegram.exe /F
- firefox.exe
- %TEMP%\pkg-a2tpcv\d093676ff7f72b93d21cd1cb809167ab2198868f990eac8ab7dd4d196f33f18d
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\binding.gyp
- %TEMP%\pkg-a2tpcv\455dda47a3fc2f58ab06d8e526f490ec43d0fc23a5ea80dd0942644397316d9b
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\license
- %TEMP%\pkg-a2tpcv\6a9c2d4d44dd19df031a56c0db11f9b6f64138f29dc7504d89d78ed2e3a9753f
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\package.json
- %TEMP%\pkg-a2tpcv\f8eb2771c191ead4508d9bc8098ff68c312e6fa957763657c5268b3a26e3e4e0
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\readme.md
- %TEMP%\pkg-a2tpcv\c9b1a016c730343f62cbece4401fd77c662d180f63ab034735d94ff2dad382ad
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\dist\index.d.ts
- %TEMP%\pkg-a2tpcv\3043aeba077d86d8b2e7fbbd6e1ecc3438c65ab184a2bda9fa0179976c5b0170
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\dist\index.js
- %TEMP%\pkg-a2tpcv\18280b1135123aff82fbf4188a5aadfc9a5d6fffad9309f72f347f380f2da550
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\src\dpapi_addon.h
- %TEMP%\pkg-a2tpcv\7c03cec11c438b6d2512239477d9f1b45d6e16763122a3a36458ab339f50d3c4
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\src\dpapi_not_supported.cpp
- %TEMP%\pkg-a2tpcv\da37b02fb0babb651244479ea019d229fff1c41ecde74bc06335b5e603d9b30e
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\src\dpapi_win.cpp
- %TEMP%\pkg-a2tpcv\1ada21451bab629832372d519e366bfb08c80facfefe5a40c76a4f10a697c905
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\src\main.cpp
- %TEMP%\pkg-a2tpcv\6351f9f605db458fbda95baadf20ba578bd94963f17000c89a1cd00979765c53
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\test\dpapi.spec.ts
- %TEMP%\pkg-a2tpcv\251abd80280b1efda1bd4622826e2251e57fa6d72118efc1239f149a1fb7d06a
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\prebuilds\win32-arm64\@primno+dpapi.node
- %TEMP%\pkg-a2tpcv\f745c262a26e789bd92ab875007cfba9b98f0abcbc5c5606b7e98f8191726d34
- %HOMEPATH%\.cache\pkg\386e7a520b143aa7b6fa1a28a0237391a938bbedd0b245733a3da3a215026a3f\@primno\dpapi\prebuilds\win32-x64\@primno+dpapi.node
- %TEMP%\pkg-a2tpcv\5ad24cd4d19ef03079717bd6309fe0604c2a4829cd92788ebf6da95c41d3d28f
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\package.json
- %TEMP%\pkg-a2tpcv\8d6b400ae7f69a80d0cdd37a968d7b9a913661fa53475e5b8de49dda21684973
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\sqlite3.js
- %TEMP%\pkg-a2tpcv\762c7a74d7f92860a3873487b68e89f654a21d2aaeae9524eab5de9c65e66a9c
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\sqlite3-binding.js
- %TEMP%\pkg-a2tpcv\d06caec6136120c6fb7ee3681b1ca949e8b634e747ea8d3080c90f35aeb7728f
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\lib\trace.js
- %TEMP%\pkg-a2tpcv\b9a7b76665d92af2d90cc6a15ffdc1a79635559cbc1c40bd1f83c4c4449cd442
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\build\release\node_sqlite3.node
- %TEMP%\pkg-a2tpcv\89bd6d32c9e56eab63f3f62b96080aa43afa530675701610d74793d4719d1137
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\package.json
- %TEMP%\pkg-a2tpcv\ad28644733a1ac0ebdf0fa39d9ae6482a7c5fe76a3878ca66fd3dc5eee1af1e7
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\index.js
- %TEMP%\pkg-a2tpcv\4c3e1e44b29724599d5d5ae53604ce6d4da7177365b7d4ab17a0747c8e5e99fe
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\create.js
- %TEMP%\pkg-a2tpcv\6e1d4fd9353fda202cb44860615be56e031a9274f18841c86dd0b974abfd6760
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\extract.js
- %TEMP%\pkg-a2tpcv\a856006693499f10e3b9ff08dc0a81bfe54451322c3a1312d891fac5fc150c7e
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\get-write-flag.js
- %TEMP%\pkg-a2tpcv\6b079e47828607accf5e5e2a259d412b891a5a8fcc151bec8df4e2c5341ac8b3
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\header.js
- %TEMP%\pkg-a2tpcv\0296c4419ccb96b4aab5dfe04e46982c83d5cd30c099a65b5b037f5c223d062f
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\high-level-opt.js
- %TEMP%\pkg-a2tpcv\1dce0c5a838ccb7b18771bf9f5e29b7cf4d872d73907e191b82acc9c648a2223
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\large-numbers.js
- %TEMP%\pkg-a2tpcv\41d395e719379cfbfc46e23ea552998962133cbc667bb349f540de3656e2feeb
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\list.js
- %TEMP%\pkg-a2tpcv\48a264aa941ab08797810bc87b1ee5c9fdc53dc178c8a0fe9113d87823c1b48a
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\mkdir.js
- %TEMP%\pkg-a2tpcv\9aa82db6007df25931a731dc4f83c455d56dd808fe5802c3fb2c8bf637138506
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\mode-fix.js
- %TEMP%\pkg-a2tpcv\192505541597c027340e66bea4421387a6e06c0867a22e49a5016008cdf0f362
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\normalize-unicode.js
- %TEMP%\pkg-a2tpcv\d585da94804cf3c623eda666c6068bc513b5f3bed1fa44e0f15bcc98b38fbdd2
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\normalize-windows-path.js
- %TEMP%\pkg-a2tpcv\6975602d45b540af44195bc60f0812fa76193481ecad7093f4e3b1c9dcd6f9f4
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\pack.js
- %TEMP%\pkg-a2tpcv\5df89cafb5a74fda979fce7140181d2704799af9aa54e9325454c8d13028e7c5
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\parse.js
- %TEMP%\pkg-a2tpcv\99c5c411dd9597070aa2cbba6b0cc18834f0c2550fe5c9bb14daa2a6a0869299
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\path-reservations.js
- %TEMP%\pkg-a2tpcv\c127dd86c3a743c3305afa09de0452acaa8e50da9aa8a1938f9e2451b29ef7ce
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\pax.js
- %TEMP%\pkg-a2tpcv\2ac36be9440f3d81278c9a5fae4a48dc7207facad366f9de5453daf0ca7aa559
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\read-entry.js
- %TEMP%\pkg-a2tpcv\a96ae4a25bbc043cb664738828d222780dd28cb74b244dd01a8cd4bfa198febc
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\replace.js
- %TEMP%\pkg-a2tpcv\510caa3452390a12499663048e42f67e056ff2cbb7a5f8e72e38f00b856fc709
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\strip-absolute-path.js
- %TEMP%\pkg-a2tpcv\5b8dd9c3aa3c76a691a4a2e953d9d515bf4caee6281a1c7ea83ee78174957d08
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\strip-trailing-slashes.js
- %TEMP%\pkg-a2tpcv\d4de2e5c48d89e3c6666063ff45d1ffbe9dc975b7262903267c824b8f596910e
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\types.js
- %TEMP%\pkg-a2tpcv\665c35a372a9021781ba5611cb269b91f20ccc1ef6182ef47ad284d2fb8a3adf
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\unpack.js
- %TEMP%\pkg-a2tpcv\e451dff75ce154f2c43384937f68d0c914cd4f13b208838c566a3bb91e985be4
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\update.js
- %TEMP%\pkg-a2tpcv\68a0872c9747368a95918d2623d8ee5686c4f41951975512e952491c43fc17f0
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\warn-mixin.js
- %TEMP%\pkg-a2tpcv\5cb97674101a0d79920df164ba402c8da0941960823daab3a16c8b06a12a1aed
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\winchars.js
- %TEMP%\pkg-a2tpcv\8f57032e81a8afc349fc1299da58598dc414d7c7ea27cb47e8a28b265a983f73
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\tar\lib\write-entry.js
- %TEMP%\pkg-a2tpcv\280af43113a60826e63a6bf79e115fdf5f89d5866f663cdde3d229640671cee1
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\minipass\package.json
- %TEMP%\pkg-a2tpcv\cada1f100f58d05055afead733ec4bdb743e1e3333ab0e899a24f50c88c20cce
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\minipass\index.js
- %TEMP%\pkg-a2tpcv\02808b78f0324c25fe6793f3ead20907e5007437aff31b581e86f9b55263e483
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\minipass\index.d.ts
- %TEMP%\pkg-a2tpcv\00610cfd77dad5aa627d77f31362d4ba0f0a7db96902caf15451c9c637dd8d9e
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\minipass\index.mjs
- %TEMP%\pkg-a2tpcv\a7357d86be1fd6cd9ac7bc78c4d49155ce08c6087a2378fae5b15ce2eb34b9a2
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\package.json
- %TEMP%\pkg-a2tpcv\fd78d08648851e2db1b19e1271a90ad55b640d0b6ae2b20ad11c94aeec847b33
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\index.js
- %TEMP%\pkg-a2tpcv\a5bf5e02584a7d72e4954f45e6efd60965315a78237179072de58cd8a161b8b6
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\bin\cmd.js
- %TEMP%\pkg-a2tpcv\743b7fd8fd5ec11dd6a71800650a65079f5bd3f08cbabb5c8dfadf06d138d755
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\find-made.js
- %TEMP%\pkg-a2tpcv\492bedcd991014695803a3788f6c520df9c9b46fc315c9237debfdb713d75aaf
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\mkdirp-manual.js
- %TEMP%\pkg-a2tpcv\bb01894bca455d7cc47c4957687293ef0fa740fc50e9af1351517e7ad667d00a
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\mkdirp-native.js
- %TEMP%\pkg-a2tpcv\a9a3e4f1700201c1ecb1d5ebb33d6da69ecf3db23546c4d077c730ae42a0a6a9
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\opts-arg.js
- %TEMP%\pkg-a2tpcv\93abafb7a89f0fe00c662cd8f4100f4aeef7d5b0a068b8a9af81b38f03d21325
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\path-arg.js
- %TEMP%\pkg-a2tpcv\fed1e14f4d3a650493666697889e77ebb3be6ccb6054e9f55197566d1cf0eea8
- %HOMEPATH%\.cache\pkg\f806f89dc41dde00ca7124dc1e649bdc9b08ff2eff5c891b764f3e5aefa9548c\sqlite3\node_modules\mkdirp\lib\use-native.js
- nul
- %LOCALAPPDATA%\microsoft\edge\user data\devtoolsactiveport
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\gpucache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies-journal
- %LOCALAPPDATA%\microsoft\edge\user data\default\cookies
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\index
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_0
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_2
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\data_3
- %LOCALAPPDATA%\microsoft\edge\user data\default\chrome_debug.log
- %LOCALAPPDATA%\microsoft\edge\user data\default\cache\f_000001
- %LOCALAPPDATA%\microsoft\edge\user data\default\code cache\js\4233171093f94bbb_0
- 'localhost':5556
- 'mail.google.com':443
- 'pk#.goog':80
- 'accounts.google.com':443
- 'gs##tic.com':443
- http://pk#.goog/gsr1/gsr1.crt
- 'localhost':49695
- 'mail.google.com':443
- 'accounts.google.com':443
- 'gs##tic.com':443
- 'fo###.gstatic.com':443
- DNS ASK mail.google.com
- DNS ASK pk#.goog
- DNS ASK accounts.google.com
- DNS ASK gs##tic.com
- DNS ASK fo###.gstatic.com
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /d /s /c "tasklist"
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\cmd.exe' /d /s /c "taskkill /f /t /im firefox.exe"
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --disable-field-trial-config --disable-background-networking --disable-background-timer-throttling --disable-backgrounding-occluded-windows --disable-back-forward-cache --disable-breakpad --dis...
- '<SYSTEM32>\cmd.exe' /d /s /c ""%APPDATA%\malfex\chrome_inject_x64.exe" --verbose chrome"
- '<SYSTEM32>\cmd.exe' /d /s /c "taskkill /IM Telegram.exe /F"
- '<SYSTEM32>\cmd.exe' /d /s /c "tasklist"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /d /s /c "taskkill /f /t /im firefox.exe"' (with hidden window)
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --disable-field-trial-config --disable-background-networking --disable-background-timer-throttling --disable-backgrounding-occluded-windows --disable-back-forward-cache --disable-breakpad --dis...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /d /s /c ""%APPDATA%\malfex\chrome_inject_x64.exe" --verbose chrome"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /d /s /c "taskkill /IM Telegram.exe /F"' (with hidden window)