Technical Information
- <SYSTEM32>\arquivo2.exe
- <SYSTEM32>\arquivo3.exe
- <SYSTEM32>\arquivo1.exe
- <SYSTEM32>\arquivo3.exe (downloaded from the Internet)
- <SYSTEM32>\arquivo1.exe (downloaded from the Internet)
- <SYSTEM32>\arquivo2.exe (downloaded from the Internet)
- <SYSTEM32>\arquivo2.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\2VAZY7AN\arquivo3[1].jpg
- <SYSTEM32>\arquivo3.exe
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\U98D4X8H\arquivo2[1].jpg
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\arquivo1[1].jpg
- <SYSTEM32>\arquivo1.exe
- 'fo########.dominiotemporario.com':80
- 'localhost':1036
- fo########.dominiotemporario.com/srv/arquivo3.jpg
- fo########.dominiotemporario.com/srv/arquivo2.jpg
- fo########.dominiotemporario.com/srv/arquivo1.jpg
- DNS ASK fo########.dominiotemporario.com
- '<Private IP address>':1037