Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Syshost' = '"%APPDATA%\syshost.exe"'
- <SYSTEM32>\tasks\windows security checks
- <SYSTEM32>\sihost.exe
- %WINDIR%\explorer.exe
- <SYSTEM32>\runtimebroker.exe
- msedge.exe
- rxdwxxqg.exe process, Amsi.dll module
- rxdwxxqg.exe process, ntdll.dll module
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions]
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %APPDATA%\mozilla\firefox\profiles.ini
- %HOMEPATH%\desktop\sdksampleunprivdeveloper.cer
- %HOMEPATH%\desktop\testcertificate.cer
- %HOMEPATH%\desktop\hanni_umami_chapter.doc
- %APPDATA%\microsoft\windows\services\wlrmdr.exe
- %TEMP%\jn6xpg3z.exe
- %TEMP%\nx1tolmv.exe
- %TEMP%\i1daxs2z.exe
- %TEMP%\is-foh1w3ovh4.tmp\i1daxs2z.tmp
- %TEMP%\is-p8kifpx6k9.tmp\_isetup\_isdecmp.dll
- %TEMP%\9f17bf9b8ad74c3eaf7e.exe
- %TEMP%\d8697301ba2d483cbe95.exe
- %APPDATA%\syshost.exe
- %TEMP%\is-wlb5xnuley.tmp\9f17bf9b8ad74c3eaf7e.tmp
- %TEMP%\is-7nvcp41h7x.tmp\_isetup\_isdecmp.dll
- %TEMP%\ed5hn59h.exe
- %APPDATA%\microsoft\windows\services\wlrmdr.exe
- %APPDATA%\syshost.exe
- 'google.com':80
- 'bing.com':80
- '19#.#78.158.107':80
- http://www.google.com/
- http://www.bing.com/
- http://19#.#78.158.107/vbv/get.php?ui######################################################
- http://19#.#78.158.107/vbv/get.php?ui#################################################################################
- http://19#.#78.158.107/vbv/get.php?ui#######################################################
- http://19#.#78.158.107/vbv/get.php?ui##############################################################
- http://19#.#78.158.107/auth.php
- DNS ASK google.com
- DNS ASK bing.com
- '%TEMP%\jn6xpg3z.exe'
- '%TEMP%\nx1tolmv.exe'
- '%TEMP%\i1daxs2z.exe'
- '%TEMP%\is-foh1w3ovh4.tmp\i1daxs2z.tmp' /SL5="$120278,3755066,888832,%TEMP%\i1daxs2z.exe"
- '%TEMP%\d8697301ba2d483cbe95.exe'
- '%APPDATA%\syshost.exe'
- '%TEMP%\9f17bf9b8ad74c3eaf7e.exe'
- '%TEMP%\is-wlb5xnuley.tmp\9f17bf9b8ad74c3eaf7e.tmp' /SL5="$70168,3755066,888832,%TEMP%\9F17BF9B8AD74C3EAF7E.exe"
- '%TEMP%\ed5hn59h.exe'
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --no-sandbox
- '<SYSTEM32>\cmd.exe' /c "netsh wlan export profile key=clear folder="%TEMP%\dia_wifi_tmp\" 2>nul"
- '<SYSTEM32>\netsh.exe' wlan export profile key=clear folder="%TEMP%\dia_wifi_tmp\"
- '<SYSTEM32>\cmd.exe' /c "netsh wlan export profile key=clear folder="%TEMP%\dia_wifi_tmp\" 2>nul"' (with hidden window)
- '%TEMP%\d8697301ba2d483cbe95.exe' ' (with hidden window)
- '%APPDATA%\syshost.exe' ' (with hidden window)
- '%TEMP%\9f17bf9b8ad74c3eaf7e.exe' ' (with hidden window)