Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Snetchball' = '%APPDATA%\Snetchball\Snetchball.exe'
- %TEMP%\nsvb8a4.tmp
- %APPDATA%\snetchball\locales\ml.pak
- %APPDATA%\snetchball\locales\lv.pak
- %APPDATA%\snetchball\locales\lt.pak
- %APPDATA%\snetchball\locales\ko.pak
- %APPDATA%\snetchball\locales\kn.pak
- %APPDATA%\snetchball\locales\ja.pak
- %APPDATA%\snetchball\locales\it.pak
- %APPDATA%\snetchball\locales\id.pak
- %APPDATA%\snetchball\locales\hu.pak
- %APPDATA%\snetchball\locales\hr.pak
- %APPDATA%\snetchball\locales\hi.pak
- %APPDATA%\snetchball\locales\he.pak
- %APPDATA%\snetchball\locales\gu.pak
- %APPDATA%\snetchball\locales\fr.pak
- %APPDATA%\snetchball\locales\fil.pak
- %APPDATA%\snetchball\locales\fi.pak
- %APPDATA%\snetchball\locales\fa.pak
- %APPDATA%\snetchball\locales\mr.pak
- %APPDATA%\snetchball\locales\ms.pak
- %APPDATA%\snetchball\locales\nb.pak
- %APPDATA%\snetchball\locales\nl.pak
- %APPDATA%\snetchball\locales\zh-tw.pak
- %APPDATA%\snetchball\locales\zh-cn.pak
- %APPDATA%\snetchball\locales\vi.pak
- %APPDATA%\snetchball\locales\uk.pak
- %APPDATA%\snetchball\locales\tr.pak
- %APPDATA%\snetchball\locales\th.pak
- %APPDATA%\snetchball\locales\te.pak
- %APPDATA%\snetchball\locales\ta.pak
- %APPDATA%\snetchball\locales\sv.pak
- %APPDATA%\snetchball\locales\sw.pak
- %APPDATA%\snetchball\locales\sr.pak
- %APPDATA%\snetchball\locales\sl.pak
- %APPDATA%\snetchball\locales\sk.pak
- %APPDATA%\snetchball\locales\ru.pak
- %APPDATA%\snetchball\locales\ro.pak
- %APPDATA%\snetchball\locales\pt-pt.pak
- %APPDATA%\snetchball\locales\pt-br.pak
- %APPDATA%\snetchball\locales\pl.pak
- %TEMP%\nss6ed6.tmp\litefirewall.dll
- %APPDATA%\snetchball\locales\et.pak
- %APPDATA%\snetchball\locales\es.pak
- %APPDATA%\snetchball\locales\es-419.pak
- %APPDATA%\snetchball\d3dcompiler_43.dll
- %APPDATA%\snetchball\chrome_elf.dll
- %APPDATA%\snetchball\cef_extensions.pak
- %APPDATA%\snetchball\cef_200_percent.pak
- %APPDATA%\snetchball\cef_100_percent.pak
- %APPDATA%\snetchball\cef.pak
- %APPDATA%\snetchball\xilium.cefglue.xml
- %APPDATA%\snetchball\xilium.cefglue.dll
- %APPDATA%\snetchball\snetchball.exe
- %APPDATA%\snetchball\newtonsoft.json.dll
- %APPDATA%\snetchball\mousekeyboardactivitymonitor.dll
- %APPDATA%\snetchball\ionic.zip.dll
- %APPDATA%\snetchball\del.exe
- %TEMP%\nss15f7.tmp
- %TEMP%\setup.exe
- %TEMP%\nslb8b5.tmp\inetc.dll
- %TEMP%\nslb8b5.tmp\nsprocess.dll
- %APPDATA%\snetchball\d3dcompiler_47.dll
- %APPDATA%\snetchball\devtools_resources.pak
- %APPDATA%\snetchball\icudtl.dat
- %APPDATA%\snetchball\libegl.dll
- %APPDATA%\snetchball\locales\en-gb.pak
- %APPDATA%\snetchball\locales\el.pak
- %APPDATA%\snetchball\locales\de.pak
- %APPDATA%\snetchball\locales\da.pak
- %APPDATA%\snetchball\locales\cs.pak
- %APPDATA%\snetchball\locales\ca.pak
- %APPDATA%\snetchball\locales\bn.pak
- %APPDATA%\snetchball\locales\bg.pak
- %APPDATA%\snetchball\locales\am.pak
- %APPDATA%\snetchball\locales\ar.pak
- %APPDATA%\snetchball\widevinecdmadapter.dll
- %APPDATA%\snetchball\tetris.png
- %APPDATA%\snetchball\start.bat
- %APPDATA%\snetchball\snapshot_blob.bin
- %APPDATA%\snetchball\natives_blob.bin
- %APPDATA%\snetchball\log4net.dll
- %APPDATA%\snetchball\libcef.dll
- %APPDATA%\snetchball\libglesv2.dll
- %APPDATA%\snetchball\locales\en-us.pak
- %APPDATA%\snetchball\uninstall.exe
- %TEMP%\nss6ed6.tmp\litefirewall.dll
- %TEMP%\setup.exe
- %TEMP%\nslb8b5.tmp\inetc.dll
- %TEMP%\nslb8b5.tmp\nsprocess.dll
- http://do#####gbuttons.site/9/huge.dat
- http://ap#.#####ll-stat.debug.world/clients/installs
- http://ap#.#####ll-stat.debug.world/clients/activity
- http://su##tsk.biz/c/g
- DNS ASK do#####gbuttons.site
- DNS ASK fa###ook.com
- DNS ASK st###.#.doubleclick.net
- DNS ASK tr#.#aboola.com
- DNS ASK am######ixel.outbrain.com
- DNS ASK tr.##tbrain.com
- DNS ASK am#####.outbrain.com
- DNS ASK cd#.#aboola.com
- DNS ASK google.com
- DNS ASK co#####.facebook.net
- DNS ASK co#####.yepshare.com
- DNS ASK go.#####atemydiscount.com
- DNS ASK go#####agmanager.com
- DNS ASK go###game.com
- DNS ASK ph#####brainsula.com
- DNS ASK su##tsk.biz
- DNS ASK ap#.#####ll-stat.debug.world
- DNS ASK go#####analytics.com
- DNS ASK go##le.nl
- '%TEMP%\setup.exe'
- '%APPDATA%\snetchball\snetchball.exe'
- '%APPDATA%\snetchball\snetchball.exe' --type=renderer --no-sandbox --disable-databases --primordial-pipe-token=725D9B1944A24DF5872675451F99C514 --lang=en-US --lang=en-US --log-file=CefGlue.log --log-severity=disable --user-agent="M...