Technical Information
- %TEMP%\ixp000.tmp\comment
- %TEMP%\ixp000.tmp\ride
- %TEMP%\ixp000.tmp\malta.adts
- %TEMP%\ixp000.tmp\cookie
- %TEMP%\ixp000.tmp\trustees
- %TEMP%\ixp000.tmp\remainder.adts
- %TEMP%\ixp000.tmp\spot.adts
- %TEMP%\ixp000.tmp\bend.adts
- %TEMP%\ixp000.tmp\continuing.adts
- %TEMP%\ixp000.tmp\faces.adts
- %TEMP%\ixp000.tmp\626792\accounting.exe
- %TEMP%\ixp000.tmp\626792\k
- %TEMP%\ixp000.tmp\626792\k
- 't.#e':443
- 'tu###ul.cyou':443
- 't.#e':443
- 'tu###ul.cyou':443
- DNS ASK Um#######jxKSs.UmMLbMEQqjxKSs
- DNS ASK t.#e
- DNS ASK tu###ul.cyou
- '%TEMP%\ixp000.tmp\626792\accounting.exe' k
- '<SYSTEM32>\sc.exe' /?alksjdfhjf834827435
- '<SYSTEM32>\cmd.exe' /v /c Set egHEsWw=cmd & !egHEsWw! < Malta.adts
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\findstr.exe' /V "lift" Ride
- '<SYSTEM32>\sc.exe' /?alksjdfhjf834827435' (with hidden window)
- '<SYSTEM32>\cmd.exe' /v /c Set egHEsWw=cmd & !egHEsWw! < Malta.adts' (with hidden window)