Technical Information
- '' (downloaded from the Internet)
- C:\users\public\music\1656560836\2.rar
- C:\users\public\music\1656560836\7z.exe
- C:\users\public\music\1656560836\rundll3222.exe
- C:\users\public\music\1656560836\svchost.txt
- C:\users\public\music\1656560836\excep.tct
- C:\users\public\music\1656560836\iusb4mon.exe
- %ALLUSERSPROFILE%\360.dll
- %ALLUSERSPROFILE%\rundll3222.exe
- %ALLUSERSPROFILE%\svchost.txt
- %ALLUSERSPROFILE%\ini.ini
- C:\users\public\music\1656560836\2.rar
- C:\users\public\music\1656560836\7z.exe
- from C:\users\public\music\1656560836\iusb4mon.exe to C:\users\public\music\1656560836\iusb4mon1656560836.exe
- from C:\users\public\music\1656560836\excep.tct to C:\users\public\music\1656560836\cepp.dll
- '18#.#15.218.140':4478
- '15#.#5.172.111':10022
- http://18#.###.218.140:4478/8?=1######### via 18#.#15.218.140
- http://18#.###.218.140:4478/77 via 18#.#15.218.140
- '15#.#5.172.111':10022
- DNS ASK hu##us11.cn
- 'C:\users\public\music\1656560836\7z.exe' x C:\\Users\\Public\\Music\\1656560836\2.rar C:\\Users\\Public\\Music\\1656560836
- 'C:\users\public\music\1656560836\iusb4mon1656560836.exe' -a
- 'C:\users\public\music\1656560836\7z.exe' x C:\\Users\\Public\\Music\\1656560836\2.rar C:\\Users\\Public\\Music\\1656560836' (with hidden window)
- 'C:\users\public\music\1656560836\iusb4mon1656560836.exe' -a' (with hidden window)