Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %HOMEPATH%\desktop\alert.html
- %HOMEPATH%\desktop\dashborder_96.bmp
- %HOMEPATH%\desktop\dialmap.bmp
- %APPDATA%\opera software\opera stable\login data
- %TEMP%\stealerium-latest.log
- %TEMP%\tmp7de0.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\gaming\steam\configs\config.vdf
- %TEMP%\tmp7fa5.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\process.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\gaming\steam\configs\dialogconfig.vdf
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\desktop.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\documents.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\pictures.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\videos.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\startup.txt
- %TEMP%\tmp7ca7.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\arrow-down.png
- %TEMP%\tmp812c.tmp.dat
- %TEMP%\tmp82f3.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\cookies.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\history.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\bookmarks.txt
- %TEMP%\tmp8371.tmp.dat
- %TEMP%\tmp8507.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\temp.txt
- %TEMP%\tmp8547.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\drive-f.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\desktop.jpg
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\downloads.txt
- %TEMP%\tmp81d9.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\bg_search_box.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\block.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\background.png
- %TEMP%\tmp707f.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\d877f783d5d3ef8c\map0
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\settings0
- %TEMP%\tmp71e6.tmp.dat
- %TEMP%\tmp7226.tmp.dat
- %TEMP%\tmp7256.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\usertag
- %TEMP%\tmp73dd.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\bookmarks.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\cookies.txt
- %TEMP%\tmp761f.tmp.dat
- %TEMP%\tmp6e9a.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\debug.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\productkey.txt
- %TEMP%\tmp78fe.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\google\cookies.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\history.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\alert.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\dashborder_96.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\toolbar.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\dialmap.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\alert.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\about.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\ituneshelpunavailable.html
- %TEMP%\tmp78ce.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\info.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\windows.txt
- %TEMP%\tmp707f.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\pictures.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\startup.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\temp.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\videos.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\gaming\steam\configs\config.vdf
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\gaming\steam\configs\dialogconfig.vdf
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\alert.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\dashborder_96.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-c\users\user\desktop\dialmap.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\about.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\alert.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\background.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\productkey.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\bg_search_box.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\block.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\ituneshelpunavailable.html
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\toolbar.bmp
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\d877f783d5d3ef8c\map0
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\settings0
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\messenger\telegram\usertag
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\debug.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\desktop.jpg
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\info.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\process.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\drive-f.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\grabber\drive-f\arrow-down.png
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\downloads.txt
- %TEMP%\tmp812c.tmp.dat
- %TEMP%\tmp6e9a.tmp.dat
- %TEMP%\tmp71e6.tmp.dat
- %TEMP%\tmp7226.tmp.dat
- %TEMP%\tmp7256.tmp.dat
- %TEMP%\tmp73dd.tmp.dat
- %TEMP%\tmp761f.tmp.dat
- %TEMP%\tmp78ce.tmp.dat
- %TEMP%\tmp78fe.tmp.dat
- %TEMP%\tmp7ca7.tmp.dat
- %TEMP%\tmp7de0.tmp.dat
- %TEMP%\tmp7fa5.tmp.dat
- %TEMP%\tmp81d9.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\desktop.txt
- %TEMP%\tmp82f3.tmp.dat
- %TEMP%\tmp8371.tmp.dat
- %TEMP%\tmp8507.tmp.dat
- %TEMP%\tmp8547.tmp.dat
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\bookmarks.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\cookies.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\firefox\history.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\google\cookies.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\bookmarks.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\cookies.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\browsers\opera\history.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\directories\documents.txt
- %LOCALAPPDATA%\5d659b7373a846511a86597a0e3483df\user@dbityahsa_en-us\system\windows.txt
- 'ip##pi.com':80
- 'di##ord.com':443
- 'ic###azip.com':80
- http://ip##pi.com/line/?fi############
- http://ic###azip.com/
- 'di##ord.com':443
- DNS ASK ip##pi.com
- DNS ASK di##ord.com
- DNS ASK ic###azip.com
- DNS ASK microsoft.com
- DNS ASK st####.rapidssl.com
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && netsh wlan show profile | findstr All
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\netsh.exe' wlan show profile
- '%WINDIR%\syswow64\findstr.exe' All
- '%WINDIR%\syswow64\cmd.exe' /C chcp 65001 && netsh wlan show networks mode=bssid
- '%WINDIR%\syswow64\netsh.exe' wlan show networks mode=bssid