Technical Information
- <SYSTEM32>\tasks\'win32'
- %WINDIR%\security\win32.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- <Current directory>\123123.exe
- <Current directory>\arac_bilgisi.pdf
- %TEMP%\client.exe-rosed_inx.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\123123.exe.log
- %LOCALAPPDATA%\adobe\color\profiles\wscrgb.icc
- %LOCALAPPDATA%\adobe\color\profiles\wsrgb.icc
- %LOCALAPPDATA%\adobe\color\acecache11.lst
- %TEMP%\a9r14g675n_1b4839c_34s.tmp
- %APPDATA%\win32.exe
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- ClassName: 'EDIT' WindowName: ''
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\security\win32.exe'
- '<Current directory>\123123.exe'
- '%TEMP%\client.exe-rosed_inx.exe'
- '%APPDATA%\win32.exe'
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "'Win32"' /tr "'%APPDATA%\Win32.exe"'' (with hidden window)
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "<Current directory>\ARAC_BILGISI.pdf"
- '<SYSTEM32>\schtasks.exe' /create /f /sc ONLOGON /RL HIGHEST /tn "'Win32"' /tr "'%APPDATA%\Win32.exe"'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\tmp6359.tmp.bat""
- '<SYSTEM32>\timeout.exe' 3