Technical Information
- <SYSTEM32>\tasks\svchost
- %TEMP%\_mei60522\vcruntime140.dll
- %TEMP%\_mei60522\_bz2.pyd
- %TEMP%\_mei60522\_decimal.pyd
- %TEMP%\_mei60522\_hashlib.pyd
- %TEMP%\_mei60522\_lzma.pyd
- %TEMP%\_mei60522\_socket.pyd
- %TEMP%\_mei60522\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei60522\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei60522\base_library.zip
- %TEMP%\_mei60522\libcrypto-3.dll
- %TEMP%\_mei60522\python313.dll
- %TEMP%\_mei60522\select.pyd
- %TEMP%\_mei60522\ucrtbase.dll
- %TEMP%\_mei60522\unicodedata.pyd
- %TEMP%\imk_ay9i
- %TEMP%\tmpjpux44nu.exe
- %TEMP%\wnffnfnf.exe
- %TEMP%\extreme injector v3.exe
- %TEMP%\content\4828-3256-wnffnfnf.exe-16-38-11-993.dump
- %APPDATA%\aimwhore\something.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\wnffnfnf.exe.log
- %TEMP%\content\4840-5056-something.exe-16-38-16-453.dump
- <SYSTEM32>\windowspowershell\v1.0\settings.xml
- %APPDATA%\aimwhore\something.exe
- %TEMP%\imk_ay9i
- %TEMP%\tmpjpux44nu.exe
- %TEMP%\_mei60522\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei60522\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei60522\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei60522\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei60522\base_library.zip
- %TEMP%\_mei60522\libcrypto-3.dll
- %TEMP%\_mei60522\python313.dll
- %TEMP%\_mei60522\select.pyd
- %TEMP%\_mei60522\ucrtbase.dll
- %TEMP%\_mei60522\unicodedata.pyd
- %TEMP%\_mei60522\vcruntime140.dll
- %TEMP%\_mei60522\_bz2.pyd
- %TEMP%\_mei60522\_decimal.pyd
- %TEMP%\_mei60522\_hashlib.pyd
- %TEMP%\_mei60522\_lzma.pyd
- %TEMP%\_mei60522\_socket.pyd
- 'pe######ass.gl.at.ply.gg':41169
- 'ra#.####ubusercontent.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK pe######ass.gl.at.ply.gg
- DNS ASK ra#.####ubusercontent.com
- '%TEMP%\tmpjpux44nu.exe'
- '%TEMP%\wnffnfnf.exe'
- '%TEMP%\extreme injector v3.exe'
- '%APPDATA%\aimwhore\something.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\tmpjpux44nu.exe"
- '<SYSTEM32>\schtasks.exe' /create /tn "svchost" /sc ONLOGON /tr "%APPDATA%\AimWhore\Something.exe" /rl HIGHEST /f
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\tmpjpux44nu.exe"' (with hidden window)
- '%TEMP%\wnffnfnf.exe' ' (with hidden window)
- '%TEMP%\extreme injector v3.exe' ' (with hidden window)