Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '%TEMP%\RarSFX0\XWormClient.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess 'XWormClient.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '%APPDATA%\XWormClient.exe'
- %TEMP%\_mei36962\vcruntime140.dll
- %TEMP%\_mei36962\_bz2.pyd
- %TEMP%\_mei36962\_cffi_backend.cp313-win_amd64.pyd
- %TEMP%\_mei36962\_decimal.pyd
- %TEMP%\_mei36962\_hashlib.pyd
- %TEMP%\_mei36962\_lzma.pyd
- %TEMP%\_mei36962\_socket.pyd
- %TEMP%\_mei36962\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-fibers-l1-1-1.dll
- %TEMP%\_mei36962\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei36962\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-kernel32-legacy-l1-1-1.dll
- %TEMP%\_mei36962\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei36962\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei36962\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei36962\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-sysinfo-l1-2-0.dll
- %TEMP%\_mei36962\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei36962\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei36962\base_library.zip
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\installer
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\metadata
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\record
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\wheel
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\licenses\license
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\licenses\license.apache
- %TEMP%\_mei36962\cryptography-45.0.6.dist-info\licenses\license.bsd
- %TEMP%\_mei36962\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei36962\libcrypto-3.dll
- %TEMP%\_mei36962\python3.dll
- %TEMP%\_mei36962\python313.dll
- %TEMP%\_mei36962\select.pyd
- %TEMP%\_mei36962\ucrtbase.dll
- %TEMP%\_mei36962\unicodedata.pyd
- %TEMP%\sv_s0s8i
- %TEMP%\tmpyngd9ikp.exe
- %TEMP%\_mei50082\vcruntime140.dll
- %TEMP%\_mei50082\_bz2.pyd
- %TEMP%\_mei50082\_decimal.pyd
- %TEMP%\_mei50082\_hashlib.pyd
- %TEMP%\_mei50082\_lzma.pyd
- %TEMP%\_mei50082\_socket.pyd
- %TEMP%\_mei50082\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-fibers-l1-1-1.dll
- %TEMP%\_mei50082\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei50082\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-kernel32-legacy-l1-1-1.dll
- %TEMP%\_mei50082\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei50082\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei50082\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei50082\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-sysinfo-l1-2-0.dll
- %TEMP%\_mei50082\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei50082\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei50082\base_library.zip
- %TEMP%\_mei50082\libcrypto-3.dll
- %TEMP%\_mei50082\python313.dll
- %TEMP%\_mei50082\select.pyd
- %TEMP%\_mei50082\ucrtbase.dll
- %TEMP%\_mei50082\unicodedata.pyd
- %TEMP%\137yzpmr
- %TEMP%\tmp166yxbum.exe
- %TEMP%\rarsfx0\xwormclient.exe
- %TEMP%\rarsfx0\dexterion_banner.jpg
- ClassName: 'Edit' WindowName: ''
- ClassName: 'NarratorUIClass' WindowName: ''
- '%TEMP%\tmpyngd9ikp.exe'
- '%TEMP%\tmp166yxbum.exe'
- '%TEMP%\rarsfx0\xwormclient.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '%TEMP%\RarSFX0\XWormClient.exe'' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionProcess 'XWormClient.exe'' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath '%APPDATA%\XWormClient.exe'' (with hidden window)