Technical Information
- %TEMP%\content\3856-1584-<File name>.exe-21-13-19-077.dump
- %TEMP%\guardian_src_945a0cc7a02c4ecaafc9e9a96139a2c9.cs
- %TEMP%\cscd60abfd815ef475cbb3f59a3c6f220fe.tmp
- %TEMP%\res409e.tmp
- %TEMP%\<File name>.exe
- %TEMP%\content\3856-1584-<File name>.exe-21-13-37-129.dump
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- %TEMP%\res409e.tmp
- %TEMP%\cscd60abfd815ef475cbb3f59a3c6f220fe.tmp
- %TEMP%\guardian_src_945a0cc7a02c4ecaafc9e9a96139a2c9.cs
- DNS ASK ke##uth.win
- '%TEMP%\<File name>.exe' 3856
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /target:exe /out:"%TEMP%\<File name>.exe" "%TEMP%\guardian_src_945a0cc7a02c4ecaafc9e9a96139a2c9.cs"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES409E.tmp" "%TEMP%\CSCD60ABFD815EF475CBB3F59A3C6F220FE.TMP"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES409E.tmp" "%TEMP%\CSCD60ABFD815EF475CBB3F59A3C6F220FE.TMP"' (with hidden window)