Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\tt.lnk
- %WINDIR%\microsoft.net\framework\v4.0.30319\mscorsvw.exe
- mscorsvw.exe
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook]
- [<HKCU>\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %HOMEPATH%\desktop\tt.exe
- %TEMP%\12329857012432811796065.tmp
- %TEMP%\12329694105866918604717.tmp
- %TEMP%\1232922732968092069543.tmp
- %TEMP%\12329078104972351532617.tmp
- %TEMP%\12211136289573436081576.tmp
- %TEMP%\122111324826813333627.tmp
- %TEMP%\1221113961551733051787.tmp
- %TEMP%\1221097747722190957073.tmp
- %TEMP%\12210978194535424828937.tmp
- %TEMP%\1221035847023414082906.tmp-shm
- %TEMP%\1221035847023414082906.tmp
- %TEMP%\12210194580629952274938.tmp
- %TEMP%\12210041987893793234293.tmp
- %TEMP%\12209575797817670729015.tmp
- %TEMP%\1220941625927946741388.tmp
- %TEMP%\1210879281212388211813.tmp
- %TEMP%\12108799945107481831973.tmp
- %TEMP%\12108329989742577081301.tmp
- %TEMP%\12107232851362610408952.tmp
- %TEMP%\12107237555969341914227.tmp
- %TEMP%\12106614768892191024819.tmp-shm
- %TEMP%\12106614768892191024819.tmp
- %TEMP%\12105835790383811699891.tmp
- %TEMP%\1233000397490782432.tmp
- %TEMP%\1233000397490782432.tmp-shm
- %TEMP%\12330478263333073655106.tmp
- %TEMP%\123306395602011317429.tmp
- %TEMP%\1255090707697053533557.tmp
- %TEMP%\12550745152569655716827.tmp
- %TEMP%\12550748792877486837741.tmp
- %TEMP%\12550596241690720719605.tmp
- %TEMP%\12550284925257282114915.tmp-shm
- %TEMP%\12550284925257282114915.tmp
- %TEMP%\12550122290971630171761.tmp
- %TEMP%\12549964048301556388454.tmp
- %TEMP%\12549034513181727823600.tmp
- %TEMP%\12548873719324887892157.tmp
- %TEMP%\1245184725266353150143.tmp
- %TEMP%\12451682776949367545277.tmp
- %TEMP%\12451845014306499512710.tmp
- %TEMP%\12451531710812186375640.tmp
- %TEMP%\12451539785284888548910.tmp
- %TEMP%\12451062508876104856.tmp-shm
- %TEMP%\12451062508876104856.tmp
- %TEMP%\1245090187631683258405.tmp
- %TEMP%\12450908534384526689870.tmp
- %TEMP%\12450286738923782314441.tmp
- %TEMP%\12450125317407574081592.tmp
- %TEMP%\123307832207444338711.tmp
- %TEMP%\12330634122838941168.tmp
- %TEMP%\12330637802871276963735.tmp
- %TEMP%\1255090590487712735761.tmp
- %TEMP%\12105676712791331439075.tmp
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %TEMP%\2fda\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-convert-l1-1-0.dll
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %TEMP%\12080716832632861896227.tmp
- %TEMP%\12080092124124055031442.tmp
- %TEMP%\2fda\vcruntime140.dll
- %TEMP%\2fda\ucrtbase.dll
- %TEMP%\2fda\softokn3.dll
- %TEMP%\2fda\nssdbm3.dll
- %TEMP%\2fda\nss3.dll
- %TEMP%\2fda\msvcp140.dll
- %TEMP%\2fda\mozglue.dll
- %TEMP%\2fda\freebl3.dll
- %TEMP%\2fda\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-private-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-environment-l1-1-0.dll
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %TEMP%\12703625213270462248600.tmp-shm
- %TEMP%\12080092124124055031442.tmp
- %TEMP%\1233000397490782432.tmp-shm
- %TEMP%\12329857012432811796065.tmp
- %TEMP%\12329694105866918604717.tmp
- %TEMP%\1232922732968092069543.tmp
- %TEMP%\12329078104972351532617.tmp
- %TEMP%\12211136289573436081576.tmp
- %TEMP%\122111324826813333627.tmp
- %TEMP%\1221113961551733051787.tmp
- %TEMP%\1221097747722190957073.tmp
- %TEMP%\12210978194535424828937.tmp
- %TEMP%\1233000397490782432.tmp
- %TEMP%\1221035847023414082906.tmp
- %TEMP%\12210194580629952274938.tmp
- %TEMP%\12210041987893793234293.tmp
- %TEMP%\12209575797817670729015.tmp
- %TEMP%\1220941625927946741388.tmp
- %WINDIR%\microsoft.net\framework\v4.0.30319\mscorsvw.exe
- %TEMP%\2fda\vcruntime140.dll
- %TEMP%\2fda\ucrtbase.dll
- %TEMP%\2fda\softokn3.dll
- %TEMP%\2fda\nssdbm3.dll
- %TEMP%\2fda\nss3.dll
- %TEMP%\1221035847023414082906.tmp-shm
- %TEMP%\12330478263333073655106.tmp
- %TEMP%\123306395602011317429.tmp
- %TEMP%\12330637802871276963735.tmp
- %TEMP%\1255090707697053533557.tmp
- %TEMP%\12550745152569655716827.tmp
- %TEMP%\12550748792877486837741.tmp
- %TEMP%\12550596241690720719605.tmp
- %TEMP%\12550284925257282114915.tmp
- %TEMP%\12550284925257282114915.tmp-shm
- %TEMP%\12550122290971630171761.tmp
- %TEMP%\12549964048301556388454.tmp
- %TEMP%\12549034513181727823600.tmp
- %TEMP%\12548873719324887892157.tmp
- %TEMP%\1245184725266353150143.tmp
- %TEMP%\12451845014306499512710.tmp
- %TEMP%\12451682776949367545277.tmp
- %TEMP%\12451531710812186375640.tmp
- %TEMP%\12451539785284888548910.tmp
- %TEMP%\12451062508876104856.tmp
- %TEMP%\12451062508876104856.tmp-shm
- %TEMP%\1245090187631683258405.tmp
- %TEMP%\12450908534384526689870.tmp
- %TEMP%\12450286738923782314441.tmp
- %TEMP%\12450125317407574081592.tmp
- %TEMP%\123307832207444338711.tmp
- %TEMP%\12330634122838941168.tmp
- %TEMP%\2fda\msvcp140.dll
- %TEMP%\1255090590487712735761.tmp
- %TEMP%\2fda\mozglue.dll
- %TEMP%\2fda\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\1210879281212388211813.tmp
- %TEMP%\12108799945107481831973.tmp
- %TEMP%\12108329989742577081301.tmp
- %TEMP%\12107232851362610408952.tmp
- %TEMP%\12107237555969341914227.tmp
- %TEMP%\12106614768892191024819.tmp
- %TEMP%\12106614768892191024819.tmp-shm
- %TEMP%\12105835790383811699891.tmp
- %TEMP%\12105676712791331439075.tmp
- %TEMP%\12080716832632861896227.tmp
- %TEMP%\2fda\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-private-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\2fda\freebl3.dll
- %TEMP%\12703625213270462248600.tmp-shm
- %TEMP%\2fda\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-multibyte-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-private-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\2fda\freebl3.dll
- %TEMP%\2fda\mozglue.dll
- %TEMP%\2fda\msvcp140.dll
- %TEMP%\2fda\nss3.dll
- %TEMP%\2fda\nssdbm3.dll
- %TEMP%\2fda\softokn3.dll
- %TEMP%\2fda\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\2fda\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\2fda\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\2fda\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\2fda\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\2fda\ucrtbase.dll
- %TEMP%\2fda\vcruntime140.dll
- http://pi##ans.com/mxnjs/index.php
- DNS ASK pi##ans.com
- '%HOMEPATH%\desktop\tt.exe'
- '%WINDIR%\syswow64\cmd.exe' /c copy "<Full path to file>" "%HOMEPATH%\Desktop\tt.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c, "%HOMEPATH%\Desktop\tt.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\timeout.exe 3 & del "mscorsvw.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c copy "<Full path to file>" "%HOMEPATH%\Desktop\tt.exe"
- '%WINDIR%\syswow64\cmd.exe' /c, "%HOMEPATH%\Desktop\tt.exe"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\mscorsvw.exe'
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\timeout.exe 3 & del "mscorsvw.exe"
- '%WINDIR%\syswow64\timeout.exe' 3