Technical Information
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\83aa4cc77f591dfc2374580bbd95f6ba_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
- %TEMP%\ytlhotk2mziymmrkmtg3mjczzwfmode3mjlmzdmyntq.exe
- %TEMP%\setup.exe
- %TEMP%\update.exe
- 'da#####ichjwclik.fun':80
- 'ne#####rhoodfeelsa.fun':80
- 'di######iremonkeyowwa.fun':80
- 'ra#####ilityframw.fun':80
- http://da#####ichjwclik.fun/api
- http://ne#####rhoodfeelsa.fun/api
- http://di######iremonkeyowwa.fun/api
- http://ra#####ilityframw.fun/api
- 'im#####lestorage.top':443
- DNS ASK im#####lestorage.top
- DNS ASK re#####ncapablewew.pw
- DNS ASK da#####ichjwclik.fun
- DNS ASK ne#####rhoodfeelsa.fun
- DNS ASK di######iremonkeyowwa.fun
- DNS ASK ra#####ilityframw.fun
- DNS ASK ca#####dsplurgrewe.pw
- DNS ASK op#####icknessopw.pw
- DNS ASK po#####rightenpowoa.pw
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\ytlhotk2mziymmrkmtg3mjczzwfmode3mjlmzdmyntq.exe'
- '%TEMP%\update.exe'
- '%TEMP%\setup.exe'
- '%TEMP%\ytlhotk2mziymmrkmtg3mjczzwfmode3mjlmzdmyntq.exe' ' (with hidden window)
- '%ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe' -Dfile.encoding=UTF-8 -classpath "<Full path to file>" org.develnext.jphp.ext.javafx.FXLauncher
- '%WINDIR%\explorer.exe' %TEMP%\YTlhOTk2MzIyMmRkMTg3MjczZWFmODE3MjlmZDMyNTQ.exe