Technical Information
- %TEMP%\is-9veuf.tmp\<File name>.tmp
- %TEMP%\is-nfg1v.tmp\_isetup\_setup64.tmp
- %TEMP%\is-nfg1v.tmp\_isetup\_shfoldr.dll
- %TEMP%\is-nfg1v.tmp\idp.dll
- %TEMP%\is-nfg1v.tmp\3alouch.exe
- %TEMP%\59-48a80-754-e8bbf-0830c5e200c33\kenessey.txt
- 'sc#######.s3.pl-waw.scw.cloud':80
- 'co###ctini.net':443
- 'microsoft.com':80
- 'sc#######.s3.pl-waw.scw.cloud':443
- 'el########wi.s3.pl-waw.scw.cloud':443
- http://sc#######.s3.pl-waw.scw.cloud/adv-cmean/i-record.exe
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- 'co###ctini.net':443
- 'sc#######.s3.pl-waw.scw.cloud':443
- DNS ASK sc#######.s3.pl-waw.scw.cloud
- DNS ASK co###ctini.net
- DNS ASK microsoft.com
- DNS ASK el########wi.s3.pl-waw.scw.cloud
- '%TEMP%\is-9veuf.tmp\<File name>.tmp' /SL5="$D0022,356111,272384,<Full path to file>"
- '%TEMP%\is-nfg1v.tmp\3alouch.exe' /S /UID=lylal220
- '%TEMP%\is-nfg1v.tmp\3alouch.exe' /S /UID=lylal220' (with hidden window)