Technical Information
- '%APPDATA%\hjc.exe'
- %APPDATA%\hjc.exe
- %TEMP%\halvernes\prelegate\udraderedes.fas
- %TEMP%\halvernes\prelegate\blomkaalshovedets.ana
- %TEMP%\halvernes\prelegate\troglyt121.mah
- %TEMP%\halvernes\prelegate\excystation.txt
- %TEMP%\halvernes\prelegate\handelsraadene\husassistent.xav
- %TEMP%\halvernes\prelegate\handelsraadene\sjlespalterne.ter
- %TEMP%\nsh44be.tmp
- %TEMP%\nsm4970.tmp\system.dll
- %TEMP%\nsc4981.tmp
- %TEMP%\nsw4d58.tmp
- %TEMP%\nsm5297.tmp
- %TEMP%\nsr56ad.tmp
- %TEMP%\nsh44be.tmp
- %TEMP%\nsc4981.tmp
- %TEMP%\nsw4d58.tmp
- %TEMP%\nsm5297.tmp
- 'ya####wakened.shop':80
- '19#.#2.81.162':80
- http://www.ya####wakened.shop/bj
- http://19#.#2.81.162/xampp/gvc/beautifulgirlwantottakeapicturewithmebecauseshebelievinguantgenabusrugtoersibbecasueshewant___suchaxwithmeshe.doc
- http://19#.#2.81.162/30333/hjc.exe
- DNS ASK ya####wakened.shop
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding