Technical Information
- <File name>.exe
- %TEMP%\content\4412-3172-<File name>.exe-13-47-05-841.dump
- %TEMP%\content\4412-3172-<File name>.exe-13-47-05-979.dump
- %TEMP%\content\4412-3172-<File name>.exe-13-47-06-058.dump
- %TEMP%\content\4412-3172-<File name>.exe-13-47-06-129.dump
- %TEMP%\content\4412-3172-<File name>.exe-13-47-06-214.dump
- %TEMP%\content\4412-3172-<File name>.exe-13-47-06-245.dump
- %TEMP%\<File name>.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- DNS ASK google.com
- '%TEMP%\<File name>.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Test-Connection www.google.com -Count 2 -BufferSize 128 -Delay 1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' Test-Connection www.google.com -Count 2 -BufferSize 128 -Delay 1' (with hidden window)