Technical Information
- %APPDATA%\Microsoft\windows\Start Menu\programs\startup\ccc.exe
- %TEMP%\nsi5513.tmp.exe
- %TEMP%\nsi5514.tmp.exe
- %TEMP%\nsn5534.tmp.dat
- %TEMP%\~nsu.tmp\au_.exe
- %TEMP%\1288989.bat
- %LOCALAPPDATA%\adobe\color\profiles\wscrgb.icc
- %LOCALAPPDATA%\adobe\color\profiles\wsrgb.icc
- %LOCALAPPDATA%\adobe\color\acecache11.lst
- %TEMP%\nsi5513.tmp.exe
- %TEMP%\1288989.bat
- from %TEMP%\nsn5534.tmp.dat to <PATH_SAMPLE>.pdf
- '%TEMP%\nsi5513.tmp.exe' /o1 "<Full path to file>" /o2 "%TEMP%\nsi5513.tmp.exe" /o3 "%TEMP%\nsi5514.tmp.exe" /o4 "%TEMP%\nsn5534.tmp.dat"
- '%TEMP%\~nsu.tmp\au_.exe' /o1 "<Full path to file>" /o2 "%TEMP%\nsi5513.tmp.exe" /o3 "%TEMP%\nsi5514.tmp.exe" /o4 "%TEMP%\nsn5534.tmp.dat" _?=%TEMP%\
- '%TEMP%\nsi5514.tmp.exe'
- '%ProgramFiles(x86)%\adobe\acrobat reader dc\reader\acrord32.exe' "<PATH_SAMPLE>.pdf"
- '%WINDIR%\syswow64\cmd.exe' %TEMP%\1288989.bat
- '%WINDIR%\syswow64\cmd.exe' %TEMP%\1288989.bat' (with hidden window)