Technical Information
- <SYSTEM32>\tasks\firefox default browser agent eb9bcf7d543b6ae0
- %APPDATA%\hewcuvt
- %APPDATA%\hewcuvt
- 'th###mmum.com':80
- http://th###mmum.com/upload/
- DNS ASK au###ney.com
- DNS ASK th###mmum.com
- DNS ASK at####pingtrips.com
- DNS ASK ku####ualaman.com
- DNS ASK re####zarazua.com
- DNS ASK na###mutlu.com
- '%APPDATA%\hewcuvt'
- '%APPDATA%\hewcuvt' ' (with hidden window)
- '<SYSTEM32>\taskeng.exe' {DD2ACE99-0BDE-45C2-B015-30E044BA2D86} S-1-5-21-1960123792-2022915161-3775307078-1001:yguqkzzdzp\user:Interactive:[1]