Technical Information
- [HKLM\System\CurrentControlSet\Services\pobus] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\pobus] 'ImagePath' = '%ALLUSERSPROFILE%\projone\potcm\pobus64.exe'
- 'pobus' %ALLUSERSPROFILE%\projone\potcm\pobus64.exe
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name=\"WinAppRule_In\" dir=in action=allow program=\"%ProgramFiles%\sqnrsg\AchieveImplement.exe\" enable=yes profile=any description=\"Inbound rule for WinAppRule\...
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name=\"WinAppRule_Out\" dir=out action=allow program=\"%ProgramFiles%\sqnrsg\AchieveImplement.exe\" enable=yes profile=any description=\"Outbound rule for WinAppRu...
- '<SYSTEM32>\netsh.exe' advfirewall firewall add rule name=\"WinDllpRule_In\" dir=in action=allow program=\"%ProgramFiles%\sqnrsg\cscte.dll\" enable=yes profile=any description=\"Inbound rule for WinDllpRule\"
- <SYSTEM32>\cmd.exe
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\kvj.jpg
- %ALLUSERSPROFILE%\projone\potcm\powfp643.sys
- %ALLUSERSPROFILE%\projone\potcm\powfp643_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\powol64.dll
- %ALLUSERSPROFILE%\projone\potcm\prntmgr32.dll
- %ALLUSERSPROFILE%\projone\potcm\prntmgr64.dll
- %ALLUSERSPROFILE%\projone\potcm\procmgr64.dll
- %ALLUSERSPROFILE%\projone\potcm\siriuv32.dll
- %ALLUSERSPROFILE%\projone\potcm\protocolfilters.dll
- %ALLUSERSPROFILE%\projone\potcm\rtfile64.dll
- %ALLUSERSPROFILE%\projone\potcm\rtinfo64.dll
- %ALLUSERSPROFILE%\projone\potcm\screenhooks32.dll
- %ALLUSERSPROFILE%\projone\potcm\scrnrcd64.dll
- %ALLUSERSPROFILE%\projone\potcm\sensinfo64.dll
- %ALLUSERSPROFILE%\projone\potcm\setuphlpr.dll
- %ALLUSERSPROFILE%\projone\potcm\poscsaver.exe
- %ALLUSERSPROFILE%\projone\potcm\powall64.dll
- %ALLUSERSPROFILE%\projone\potcm\rptcache64.dll
- %ALLUSERSPROFILE%\projone\potcm\shlext64.dll
- %ALLUSERSPROFILE%\projone\potcm\poprotect64.dll
- %ALLUSERSPROFILE%\projone\potcm\npcap_inst.exe
- %ALLUSERSPROFILE%\projone\potcm\odipus64.dll
- %ALLUSERSPROFILE%\projone\potcm\patch32.dll
- %ALLUSERSPROFILE%\projone\potcm\patch64.dll
- %ALLUSERSPROFILE%\projone\potcm\pobus64.exe
- %ALLUSERSPROFILE%\projone\potcm\poda32.exe
- %ALLUSERSPROFILE%\projone\potcm\poda64.exe
- %ALLUSERSPROFILE%\projone\potcm\podumper32.dll
- %ALLUSERSPROFILE%\projone\potcm\podumper64.dll
- %ALLUSERSPROFILE%\projone\potcm\poflt64.sys
- %ALLUSERSPROFILE%\projone\potcm\poflt64_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\pomqc3.dll
- %ALLUSERSPROFILE%\projone\potcm\pomqc364.dll
- %ALLUSERSPROFILE%\projone\potcm\poprotect664.sys
- %ALLUSERSPROFILE%\projone\potcm\nfwfp64_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\poprotect664_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\doced64.dll
- %ALLUSERSPROFILE%\projone\potcm\siriuv64.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\windlwork.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\zipit.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\mswinsck.ocx
- %ProgramFiles%\sqnrsg\achieveimplement.exe
- %ProgramFiles%\sqnrsg\cscte.dll
- %ProgramFiles%\sqnrsg\getinfom.dll
- %ProgramFiles%\sqnrsg\hbyabeihua.lib
- %ALLUSERSPROFILE%\projone\potcm\sqlcipher32.dll
- %ProgramFiles%\sqnrsg\mswinsck.ocx
- %ProgramFiles%\sqnrsg\unewaut1.dll
- %ProgramFiles%\sqnrsg\windlwork.dll
- %ProgramFiles%\sqnrsg\wyimage.dll
- %ProgramFiles%\sqnrsg\zipit.dll
- %WINDIR%\syswow64\mswinsck.ocx
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\unewaut1.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\system.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\wyimage.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\getinfom.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\cscte.dll
- %ALLUSERSPROFILE%\projone\potcm\sqlcipher64.dll
- %ALLUSERSPROFILE%\projone\potcm\ssleay32.dll
- %ALLUSERSPROFILE%\projone\potcm\ssleay64.dll
- %ALLUSERSPROFILE%\projone\potcm\swvv64.sys
- %ALLUSERSPROFILE%\projone\potcm\swvv64_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\unrar32.dll
- %ALLUSERSPROFILE%\projone\potcm\nfwfp64.sys
- %ALLUSERSPROFILE%\projone\potcm\unrar64.dll
- %ALLUSERSPROFILE%\projone\potcm\nnagent32.dll
- %ALLUSERSPROFILE%\projone\potcm\winpcap_inst.exe
- %ALLUSERSPROFILE%\projone\servaddrbackup
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg.7z
- %ALLUSERSPROFILE%\projone\potcm\log\pobus64\20241129212019_pobus64-0.log
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\hbyabeihua.lib
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\sqnrsg\achieveimplement.exe
- %ALLUSERSPROFILE%\projone\potcm\usbmgr64.dll
- %ALLUSERSPROFILE%\projone\potcm\sscanner64.dll
- %ALLUSERSPROFILE%\projone\potcm\workflow64.dll
- %ALLUSERSPROFILE%\projone\potcm\nfwfp32.sys
- %ALLUSERSPROFILE%\projone\potcm\nftdi32.sys
- %ALLUSERSPROFILE%\projone\potcm\nfentry32.dll
- %ALLUSERSPROFILE%\projone\potcm\skin\gxlogo.png
- %ALLUSERSPROFILE%\projone\potcm\skin\gxonecli
- %ALLUSERSPROFILE%\projone\potcm\skin\pochat
- %ALLUSERSPROFILE%\projone\potcm\skin\posoftmgr
- %ALLUSERSPROFILE%\projone\potcm\skin\shlext
- %ALLUSERSPROFILE%\projone\potcm\skin\sscannerwnd
- %ALLUSERSPROFILE%\projone\potcm\skin\sscreator
- %ALLUSERSPROFILE%\projone\potcm\skin\sswallpaper.jpg
- %ALLUSERSPROFILE%\projone\potcm\skin\wfchost
- %ALLUSERSPROFILE%\projone\potcm\skin\wfviewer
- %ALLUSERSPROFILE%\projone\potcm\skin\woumgr
- %ALLUSERSPROFILE%\projone\potcm\actmon64.dll
- %ALLUSERSPROFILE%\projone\potcm\anyconn64.dll
- %ALLUSERSPROFILE%\projone\potcm\skin\enced_normal.ico
- %ALLUSERSPROFILE%\projone\potcm\skin\clientinfo
- %ALLUSERSPROFILE%\projone\potcm\skin\enced_unauthorized.ico
- %ALLUSERSPROFILE%\projone\potcm\skin\dtescanner
- %ALLUSERSPROFILE%\projone\potcm\skin\bakviewer
- %ALLUSERSPROFILE%\projone\potcm\sirius32.dll
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\potcm.7z
- %ALLUSERSPROFILE%\projone\potcm\athens32.dll
- %ALLUSERSPROFILE%\projone\potcm\athens64.dll
- %ALLUSERSPROFILE%\projone\potcm\athenx32.dll
- %ALLUSERSPROFILE%\projone\potcm\athenx64.dll
- %ALLUSERSPROFILE%\projone\potcm\lang\zh_cn.json
- %ALLUSERSPROFILE%\projone\potcm\assistda.exe
- %ALLUSERSPROFILE%\wangyamonitor.dat
- %ALLUSERSPROFILE%\projone\potcm\reg.bat
- %ALLUSERSPROFILE%\projone\potcm\siriuw64.dll
- %ALLUSERSPROFILE%\projone\potcm\siriux32.dll
- %ALLUSERSPROFILE%\projone\potcm\siriux64.dll
- %ALLUSERSPROFILE%\projone\potcm\sj\11k6pcpe
- %ALLUSERSPROFILE%\projone\potcm\sj\n7v6jj0c
- %ALLUSERSPROFILE%\projone\potcm\sj\tidnqn2t
- %TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\za.exe
- %ALLUSERSPROFILE%\projone\potcm\siriuw32.dll
- %ProgramFiles%\sqnrsg\system.dll
- %ALLUSERSPROFILE%\projone\potcm\assisthost.exe
- %ALLUSERSPROFILE%\projone\potcm\backup64.dll
- %ALLUSERSPROFILE%\projone\potcm\lang\lang-2052.dll
- %ALLUSERSPROFILE%\projone\potcm\langrp64.dll
- %ALLUSERSPROFILE%\projone\potcm\leakways64.dll
- %ALLUSERSPROFILE%\projone\potcm\libcrypto-1_1.dll
- %ALLUSERSPROFILE%\projone\potcm\libcurl32.dll
- %ALLUSERSPROFILE%\projone\potcm\skin\enced_offline.ico
- %ALLUSERSPROFILE%\projone\potcm\libcurl64.dll
- %ALLUSERSPROFILE%\projone\potcm\libeay64.dll
- %ALLUSERSPROFILE%\projone\potcm\libssl-1_1.dll
- %ALLUSERSPROFILE%\projone\potcm\magichk32.dll
- %ALLUSERSPROFILE%\projone\potcm\naca32.dll
- %ALLUSERSPROFILE%\projone\potcm\nacmacwatch.dll
- %ALLUSERSPROFILE%\projone\potcm\nfapi.dll
- %ALLUSERSPROFILE%\projone\potcm\hermes32.dll
- %ALLUSERSPROFILE%\projone\potcm\libeay32.dll
- %ALLUSERSPROFILE%\projone\potcm\intcap64.dll
- %ALLUSERSPROFILE%\projone\potcm\imagent64.dll
- %ALLUSERSPROFILE%\projone\potcm\hecate32.dll
- %ALLUSERSPROFILE%\projone\potcm\gxonecli.exe
- %ALLUSERSPROFILE%\projone\potcm\clientbase32.dll
- %ALLUSERSPROFILE%\projone\potcm\clientbase64.dll
- %ALLUSERSPROFILE%\projone\potcm\clientstat.exe
- %ALLUSERSPROFILE%\projone\potcm\cryptdt.dll
- %ALLUSERSPROFILE%\projone\potcm\ctask64.dll
- %ALLUSERSPROFILE%\projone\potcm\assisths.exe
- %ALLUSERSPROFILE%\projone\potcm\deskmgr32.dll
- %ALLUSERSPROFILE%\projone\potcm\athenw32.dll
- %ALLUSERSPROFILE%\projone\potcm\docext.dll
- %ALLUSERSPROFILE%\projone\potcm\docscanner64.dll
- %ALLUSERSPROFILE%\projone\potcm\filedp64.dll
- %ALLUSERSPROFILE%\projone\potcm\frcinst32.dll
- %ALLUSERSPROFILE%\projone\potcm\gxdte64.dll
- %ALLUSERSPROFILE%\projone\potcm\gxdte64.sys
- %ALLUSERSPROFILE%\projone\potcm\athenw64.dll
- %ALLUSERSPROFILE%\projone\potcm\gxdte64_win7.sys
- %ALLUSERSPROFILE%\projone\potcm\docguard64.dll
- %LOCALAPPDATA%\wangyamonitor.dat
- '%TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\za.exe' x C:/Users/user/AppData/Local/Temp/f82a059e-a4d5-4bad-9d4a-529c8adee4b5/potcm.7z -pAb123456789 -o%ALLUSERSPROFILE%/projone -y
- '%ALLUSERSPROFILE%\projone\potcm\pobus64.exe' /i
- '%TEMP%\f82a059e-a4d5-4bad-9d4a-529c8adee4b5\za.exe' x C:/Users/user/AppData/Local/Temp/f82a059e-a4d5-4bad-9d4a-529c8adee4b5/sqnrsg.7z -pAb123456789 -oC:/Users/user/AppData/Local/Temp/f82a059e-a4d5-4bad-9d4a-529c8adee4b5 -y
- '%ALLUSERSPROFILE%\projone\potcm\pobus64.exe'
- '%ALLUSERSPROFILE%\projone\potcm\poda32.exe' 07c95fb4
- '%ALLUSERSPROFILE%\projone\potcm\assisths.exe'
- '<SYSTEM32>\cmd.exe' /c %ALLUSERSPROFILE%\projone\potcm\reg.bat
- '<SYSTEM32>\regsvr32.exe' /s shlext64.dll
- '<SYSTEM32>\cmd.exe' /c "netsh advfirewall firewall add rule name=\"WinAppRule_In\" dir=in action=allow program=\"%ProgramFiles%\sqnrsg\AchieveImplement.exe\" enable=yes profile=any description=\"Inbound rule for W...
- '<SYSTEM32>\cmd.exe' /c "netsh advfirewall firewall add rule name=\"WinAppRule_Out\" dir=out action=allow program=\"%ProgramFiles%\sqnrsg\AchieveImplement.exe\" enable=yes profile=any description=\"Outbound rule fo...
- '<SYSTEM32>\cmd.exe' /c "netsh advfirewall firewall add rule name=\"WinDllpRule_In\" dir=in action=allow program=\"%ProgramFiles%\sqnrsg\cscte.dll\" enable=yes profile=any description=\"Inbound rule for WinDllpRule...
- '%ALLUSERSPROFILE%\projone\potcm\assisths.exe' ' (with hidden window)