Technical Information
- %TEMP%\guardian_src_12d5b5e2b4a246af9afd12fb0677b383.cs
- %TEMP%\cscbc5bd356b9804787ab538fe99140ff91.tmp
- %TEMP%\res2bee.tmp
- %TEMP%\<File name>.exe
- %TEMP%\res2bee.tmp
- %TEMP%\cscbc5bd356b9804787ab538fe99140ff91.tmp
- %TEMP%\guardian_src_12d5b5e2b4a246af9afd12fb0677b383.cs
- DNS ASK ke##uth.win
- DNS ASK gh####uthtool.com
- '%TEMP%\<File name>.exe' 2404
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\csc.exe' /target:exe /out:"%TEMP%\<File name>.exe" "%TEMP%\guardian_src_12d5b5e2b4a246af9afd12fb0677b383.cs"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2BEE.tmp" "%TEMP%\CSCBC5BD356B9804787AB538FE99140FF91.TMP"
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2BEE.tmp" "%TEMP%\CSCBC5BD356B9804787AB538FE99140FF91.TMP"' (with hidden window)