Technical Information
- %WINDIR%\runn\windowstask.exe
- %WINDIR%\runn\duilib_u.dll
- %WINDIR%\runn\sqlite3.dll
- %WINDIR%\runn\yloux.exe
- %WINDIR%\runn\1.bin
- %LOCALAPPDATA%\{aaf6b385-8050-4338-ac46-83fa40471e43}\windowstask.lnk
- %TEMP%\{24471cfe-a512-476b-b664-57d1151b634d}.exe
- %TEMP%\{2968b816-a55c-46fb-9801-cc93cad0f347}
- %TEMP%\hi-013{cf6e2715-488f-4e5f-bbd3-d0096408309c}\{4511abff-0503-4891-94f4-838ec301c757}.lnk
- %TEMP%\regworkshop.ini
- %TEMP%\hi-013{cf6e2715-488f-4e5f-bbd3-d0096408309c}\{4511abff-0503-4891-94f4-838ec301c757}.lnk
- %TEMP%\{24471cfe-a512-476b-b664-57d1151b634d}.exe
- %TEMP%\{2968b816-a55c-46fb-9801-cc93cad0f347}
- '38.##.101.181':80
- '38.##.204.65':53261
- '10#.#43.183.201':18479
- http://38.##.204.65:53261/VSaySomething.exe via 38.##.204.65
- '10#.#43.183.201':18479
- '<LOCALNET>.1.2':6341
- '%WINDIR%\runn\yloux.exe'
- '%TEMP%\{24471cfe-a512-476b-b664-57d1151b634d}.exe' /s "%TEMP%\\{2968B816-A55C-46fb-9801-CC93CAD0F347}"
- '%WINDIR%\runn\yloux.exe' ' (with hidden window)