Technical Information
- %HOMEPATH%\Start Menu\Programs\Startup\notepad.url
- %TEMP%\2mhxcql0.0.cs
- %TEMP%\2mhxcql0.cmdline
- %TEMP%\2mhxcql0.out
- %TEMP%\2mhxcql0.pdb
- %TEMP%\CSC1.tmp
- %TEMP%\RES2.tmp
- %TEMP%\2mhxcql0.dll
- %HOMEPATH%\<File name>.exe
- %APPDATA%\Logs\04-04-2018
- %TEMP%\RES2.tmp
- %TEMP%\CSC1.tmp
- %TEMP%\2mhxcql0.pdb
- %TEMP%\2mhxcql0.dll
- %TEMP%\2mhxcql0.cmdline
- %TEMP%\2mhxcql0.0.cs
- %TEMP%\2mhxcql0.out
- 'ip##pi.com':80
- 'fr###eoip.net':80
- 'ap#.#pify.org':80
- 'ra####.ddnsgeek.com':7071
- '18#.#08.211.90':7071
- http://ip##pi.com/json/
- http://fr###eoip.net/xml/
- http://ap#.#pify.org/
- DNS ASK ip##pi.com
- DNS ASK fr###eoip.net
- DNS ASK ap#.#pify.org
- DNS ASK ra####.ddnsgeek.com
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\csc.exe' /noconfig /fullpaths @"%TEMP%\2mhxcql0.cmdline"
- '%WINDIR%\Microsoft.NET\Framework\v4.0.30319\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2.tmp" "%TEMP%\CSC1.tmp"