Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %TEMP%\_mei21122\vcruntime140.dll
- %TEMP%\_mei21122\_bz2.pyd
- %TEMP%\_mei21122\_decimal.pyd
- %TEMP%\_mei21122\_hashlib.pyd
- %TEMP%\_mei21122\_lzma.pyd
- %TEMP%\_mei21122\_socket.pyd
- %TEMP%\_mei21122\base_library.zip
- %TEMP%\_mei21122\libcrypto-1_1.dll
- %TEMP%\_mei21122\python310.dll
- %TEMP%\_mei21122\select.pyd
- %TEMP%\_mei21122\unicodedata.pyd
- %TEMP%\ekwv9a2s
- %TEMP%\winstore.app.exe
- %TEMP%\_mei11082\vcruntime140.dll
- %TEMP%\_mei11082\_asyncio.pyd
- %TEMP%\_mei11082\_bz2.pyd
- %TEMP%\_mei11082\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei11082\_ctypes.pyd
- %TEMP%\_mei11082\_decimal.pyd
- %TEMP%\_mei11082\_hashlib.pyd
- %TEMP%\_mei11082\_lzma.pyd
- %TEMP%\_mei11082\_multiprocessing.pyd
- %TEMP%\_mei11082\_overlapped.pyd
- %TEMP%\_mei11082\_queue.pyd
- %TEMP%\_mei11082\_socket.pyd
- %TEMP%\_mei11082\_sqlite3.pyd
- %TEMP%\_mei11082\_ssl.pyd
- %TEMP%\_mei11082\base_library.zip
- %TEMP%\_mei11082\certifi\cacert.pem
- %TEMP%\_mei11082\charset_normalizer\md.cp310-win_amd64.pyd
- %TEMP%\_mei11082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei11082\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei11082\libcrypto-1_1.dll
- %TEMP%\_mei11082\libffi-7.dll
- %TEMP%\_mei11082\libssl-1_1.dll
- %TEMP%\_mei11082\pyexpat.pyd
- %TEMP%\_mei11082\python3.dll
- %TEMP%\_mei11082\python310.dll
- %TEMP%\_mei11082\select.pyd
- %TEMP%\_mei11082\sqlite3.dll
- %TEMP%\_mei11082\unicodedata.pyd
- %TEMP%\age8jm0d
- nul
- %TEMP%\microsoft_vc_redist\system_info.txt
- %TEMP%\microsoft_vc_redist\discord_tokens.txt
- %TEMP%\microsoft_vc_redist\chrome_logins_temp.db
- %TEMP%\microsoft_vc_redist\edge_logins_temp.db
- %TEMP%\microsoft_vc_redist\all_browser_logins.json
- %TEMP%\microsoft_vc_redist\browser_logins_readable.txt
- %TEMP%\microsoft_vc_redist\chrome_cookies_temp.db
- %TEMP%\microsoft_vc_redist\all_browser_cookies.json
- %TEMP%\microsoft_vc_redist\chrome_history_temp.db
- %TEMP%\microsoft_vc_redist\edge_history_temp.db
- %TEMP%\microsoft_vc_redist\all_browser_history.json
- %TEMP%\microsoft_vc_redist\firefox_history_temp.db
- %TEMP%\microsoft_vc_redist\firefox_history_temp.db-shm
- %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db
- %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db-shm
- %TEMP%\microsoft_vc_redist\firefox_data.json
- %TEMP%\microsoft_vc_redist\browser_data_summary.txt
- %TEMP%\microsoft_vc_redist\decrypted_browser_data.json
- %TEMP%\microsoft_vc_redist\network_info.txt
- %TEMP%\vc_redist_part_1.zip
- %TEMP%\ekwv9a2s
- %TEMP%\_mei21122\base_library.zip
- %TEMP%\_mei21122\libcrypto-1_1.dll
- %TEMP%\_mei21122\python310.dll
- %TEMP%\_mei21122\select.pyd
- %TEMP%\_mei21122\unicodedata.pyd
- %TEMP%\_mei21122\vcruntime140.dll
- %TEMP%\_mei21122\_bz2.pyd
- %TEMP%\_mei21122\_decimal.pyd
- %TEMP%\_mei21122\_hashlib.pyd
- %TEMP%\_mei21122\_lzma.pyd
- %TEMP%\_mei21122\_socket.pyd
- %TEMP%\age8jm0d
- %TEMP%\microsoft_vc_redist\chrome_logins_temp.db
- %TEMP%\microsoft_vc_redist\edge_logins_temp.db
- %TEMP%\microsoft_vc_redist\chrome_cookies_temp.db
- %TEMP%\microsoft_vc_redist\chrome_history_temp.db
- %TEMP%\microsoft_vc_redist\edge_history_temp.db
- %TEMP%\microsoft_vc_redist\firefox_history_temp.db-shm
- %TEMP%\microsoft_vc_redist\firefox_history_temp.db
- %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db-shm
- %TEMP%\microsoft_vc_redist\firefox_cookies_temp.db
- %TEMP%\microsoft_vc_redist\all_browser_cookies.json
- %TEMP%\microsoft_vc_redist\all_browser_history.json
- %TEMP%\microsoft_vc_redist\all_browser_logins.json
- %TEMP%\microsoft_vc_redist\browser_data_summary.txt
- %TEMP%\microsoft_vc_redist\browser_logins_readable.txt
- %TEMP%\microsoft_vc_redist\decrypted_browser_data.json
- %TEMP%\microsoft_vc_redist\discord_tokens.txt
- %TEMP%\microsoft_vc_redist\firefox_data.json
- %TEMP%\microsoft_vc_redist\network_info.txt
- %TEMP%\microsoft_vc_redist\system_info.txt
- %TEMP%\vc_redist_part_1.zip
- %TEMP%\_mei11082\base_library.zip
- %TEMP%\_mei11082\certifi\cacert.pem
- %TEMP%\_mei11082\charset_normalizer\md.cp310-win_amd64.pyd
- %TEMP%\_mei11082\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
- %TEMP%\_mei11082\cryptography\hazmat\bindings\_rust.pyd
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\installer
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.apache
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\licenses\license.bsd
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\metadata
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\record
- %TEMP%\_mei11082\cryptography-46.0.3.dist-info\wheel
- %TEMP%\_mei11082\libcrypto-1_1.dll
- %TEMP%\_mei11082\libffi-7.dll
- %TEMP%\_mei11082\libssl-1_1.dll
- %TEMP%\_mei11082\pyexpat.pyd
- %TEMP%\_mei11082\python3.dll
- %TEMP%\_mei11082\python310.dll
- %TEMP%\_mei11082\select.pyd
- %TEMP%\_mei11082\sqlite3.dll
- %TEMP%\_mei11082\unicodedata.pyd
- %TEMP%\_mei11082\vcruntime140.dll
- %TEMP%\_mei11082\_asyncio.pyd
- %TEMP%\_mei11082\_bz2.pyd
- %TEMP%\_mei11082\_cffi_backend.cp310-win_amd64.pyd
- %TEMP%\_mei11082\_ctypes.pyd
- %TEMP%\_mei11082\_decimal.pyd
- %TEMP%\_mei11082\_hashlib.pyd
- %TEMP%\_mei11082\_lzma.pyd
- %TEMP%\_mei11082\_multiprocessing.pyd
- %TEMP%\_mei11082\_overlapped.pyd
- %TEMP%\_mei11082\_queue.pyd
- %TEMP%\_mei11082\_socket.pyd
- %TEMP%\_mei11082\_sqlite3.pyd
- %TEMP%\_mei11082\_ssl.pyd
- 'ap#.#pify.org':443
- 'di##ord.com':443
- 'ap#.#pify.org':443
- 'di##ord.com':443
- DNS ASK ap#.#pify.org
- DNS ASK di##ord.com
- '%TEMP%\winstore.app.exe'
- '<SYSTEM32>\cmd.exe' /c "ver"
- '<SYSTEM32>\netsh.exe' wlan show profiles
- '%TEMP%\winstore.app.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c "ver"' (with hidden window)