Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'MaxLoonaFest131' = '%LOCALAPPDATA%\MaxLoonaFest131\MaxLoonaFest131.exe'
- <SYSTEM32>\tasks\firefox default browser agent 0c16aa25e19a8178
- %APPDATA%\microsoft\windows\start menu\programs\startup\fanbooster131.lnk
- <SYSTEM32>\tasks\officetrackernmp131 hr
- <SYSTEM32>\tasks\officetrackernmp131 lg
- Windows Defender
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{7A497164-75EB-4102-BEC6-AF31E7E143A5}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- [HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Group Policy Objects\{84114F2A-49F3-44AD-ACA5-F1A82EC890DC}Machine\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Extensions] 'exe' = ''
- %WINDIR%\explorer.exe
- %APPDATA%\mozilla\firefox\profiles.ini
- %APPDATA%\mozilla\firefox\profiles\m15ucxjx.default\signons.sqlite
- %APPDATA%\mozilla\firefox\profiles\v08trqk6.default-release\signons.sqlite
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\thunderbird\profiles.ini
- %APPDATA%\thunderbird\profiles\hmz1jddi.default\signons.sqlite
- %APPDATA%\thunderbird\profiles\chdgbv82.default-release\signons.sqlite
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %APPDATA%\idfbwga
- %TEMP%\posterboxvqjayiqtxbhkv\02zdbxl47cvzhistory
- %TEMP%\posterboxvktg9nbtkb5_r\qdx9itdlycrbformhistory.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\d87fzn3r3jfeweb data
- %TEMP%\posterboxvktg9nbtkb5_r\02zdbxl47cvzhistory
- %TEMP%\posterboxvktg9nbtkb5_r\3b6n2xdh3cywweb data
- %TEMP%\posterboxvqjayiqtxbhkv\qdx9itdlycrbformhistory.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\3b6n2xdh3cywweb data
- %TEMP%\posterboxvqjayiqtxbhkv\kvhrxj77cmugplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\kvhrxj77cmugplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\5lop_s5wm5ercookies
- %TEMP%\posterboxvqjayiqtxbhkv\5lop_s5wm5ercookies
- %TEMP%\posterboxvqjayiqtxbhkv\iwpfiaxutjtshistory
- %TEMP%\posterboxvktg9nbtkb5_r\iwpfiaxutjtshistory
- %TEMP%\posterboxvktg9nbtkb5_r\jx0oqi4nztiqcookies.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\jx0oqi4nztiqcookies.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\upg2lopxwc7oplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\upg2lopxwc7oplaces.sqlite
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\3ccd5499-87a8-4b10-a215-608888dd3b55.vsch
- %ALLUSERSPROFILE%\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\2f1a6504-0641-44cf-8bb5-3612d865f2e5.vsch
- %LOCALAPPDATA%\microsoft\vault\4bf4c442-9b8a-41a0-b380-dd4a704ddb28\policy.vpol
- %TEMP%\granduiavqjayiqtxbhkv\passwords.txt
- %TEMP%\granduiavktg9nbtkb5_r\passwords.txt
- %TEMP%\granduiavktg9nbtkb5_r\information.txt
- %TEMP%\granduiavqjayiqtxbhkv\information.txt
- %TEMP%\posterboxvqjayiqtxbhkv\d87fzn3r3jfeweb data
- %TEMP%\lulz7wzezh1kegb1jbqpowqedaktunbc.zip
- %TEMP%\posterboxvktg9nbtkb5_r\ei8dramayu9klogin data
- %TEMP%\posterboxvqjayiqtxbhkv\5lop_s5wm5erplaces.sqlite
- %TEMP%\9221.exe
- %TEMP%\ixp000.tmp\as0ce75.exe
- %TEMP%\ixp000.tmp\6tx8ah0.exe
- %TEMP%\ixp001.tmp\ar3mj83.exe
- %TEMP%\ixp001.tmp\5tm5ys4.exe
- %TEMP%\ixp002.tmp\sn2jt52.exe
- %TEMP%\ixp002.tmp\4is100yv.exe
- %TEMP%\ixp003.tmp\1py49yx4.exe
- %TEMP%\ixp003.tmp\3ib53ly.exe
- %WINDIR%\syswow64\grouppolicy\gpt.ini
- <SYSTEM32>\grouppolicy\machine\registry.pol
- <SYSTEM32>\grouppolicy\gpt.ini
- %LOCALAPPDATA%\maxloonafest131\maxloonafest131.exe
- %TEMP%\fanbooster131\fanbooster131.exe
- %ALLUSERSPROFILE%\ntuser.pol
- %ALLUSERSPROFILE%\officetrackernmp131\officetrackernmp131.exe
- %TEMP%\rise131m9asphalt.tmp
- %TEMP%\3cb2.exe
- %TEMP%\posterboxvktg9nbtkb5_r\d87fzn3r3jfeformhistory.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\d87fzn3r3jfeformhistory.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\02zdbxl47cvzplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\02zdbxl47cvzplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\3b6n2xdh3cywcookies.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\3b6n2xdh3cywcookies.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\ei8dramayu9klogin data
- %TEMP%\posterboxvktg9nbtkb5_r\5lop_s5wm5erplaces.sqlite
- %TEMP%\nnvyi0urjyva9tfagxe3ykfz0vm_zimv.zip
- %APPDATA%\idfbwga
- %ALLUSERSPROFILE%\tempntuser.pol
- %TEMP%\ixp003.tmp\3ib53ly.exe
- %TEMP%\posterboxvqjayiqtxbhkv\3b6n2xdh3cywweb data
- %TEMP%\posterboxvktg9nbtkb5_r\5lop_s5wm5ercookies
- %TEMP%\posterboxvqjayiqtxbhkv\5lop_s5wm5ercookies
- %TEMP%\posterboxvqjayiqtxbhkv\iwpfiaxutjtshistory
- %TEMP%\posterboxvktg9nbtkb5_r\iwpfiaxutjtshistory
- %TEMP%\posterboxvktg9nbtkb5_r\kvhrxj77cmugplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\kvhrxj77cmugplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\jx0oqi4nztiqcookies.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\jx0oqi4nztiqcookies.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\upg2lopxwc7oplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\upg2lopxwc7oplaces.sqlite
- %TEMP%\nnvyi0urjyva9tfagxe3ykfz0vm_zimv.zip
- %TEMP%\granduiavqjayiqtxbhkv\information.txt
- %TEMP%\granduiavqjayiqtxbhkv\passwords.txt
- %TEMP%\lulz7wzezh1kegb1jbqpowqedaktunbc.zip
- %TEMP%\posterboxvktg9nbtkb5_r\3b6n2xdh3cywweb data
- %TEMP%\granduiavktg9nbtkb5_r\information.txt
- %TEMP%\posterboxvktg9nbtkb5_r\qdx9itdlycrbformhistory.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\02zdbxl47cvzhistory
- %TEMP%\ixp003.tmp\1py49yx4.exe
- %ALLUSERSPROFILE%\tempntuser.pol
- %TEMP%\posterboxvktg9nbtkb5_r\d87fzn3r3jfeformhistory.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\d87fzn3r3jfeformhistory.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\02zdbxl47cvzplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\02zdbxl47cvzplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\ei8dramayu9klogin data
- %TEMP%\posterboxvktg9nbtkb5_r\3b6n2xdh3cywcookies.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\3b6n2xdh3cywcookies.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\ei8dramayu9klogin data
- %TEMP%\posterboxvqjayiqtxbhkv\d87fzn3r3jfeweb data
- %TEMP%\posterboxvqjayiqtxbhkv\5lop_s5wm5erplaces.sqlite
- %TEMP%\posterboxvqjayiqtxbhkv\02zdbxl47cvzhistory
- %TEMP%\posterboxvktg9nbtkb5_r\5lop_s5wm5erplaces.sqlite
- %TEMP%\posterboxvktg9nbtkb5_r\d87fzn3r3jfeweb data
- %TEMP%\posterboxvqjayiqtxbhkv\qdx9itdlycrbformhistory.sqlite
- %TEMP%\granduiavktg9nbtkb5_r\passwords.txt
- from %ALLUSERSPROFILE%\ntuser.pol to %ALLUSERSPROFILE%\tempntuser.pol
- %ALLUSERSPROFILE%\ntuser.pol
- 'ho####ost-file8.com':80
- '10#.#07.182.45':80
- '19#.#33.132.51':50500
- 'ip##fo.io':443
- 'db##p.com':443
- '81.##.131.34':80
- 'ma##ind.com':80
- http://10#.#07.182.45/red/line.exe
- http://www.ma##ind.com/geoip/v2.1/city/me
- http://ho####ost-file8.com/
- http://81.##.131.34/fks/index.php
- '19#.#33.132.51':50500
- 'ip##fo.io':443
- 'db##p.com':443
- DNS ASK ho####ile-host6.com
- DNS ASK ho####ost-file8.com
- DNS ASK ip##fo.io
- DNS ASK db##p.com
- DNS ASK ma##ind.com
- '%TEMP%\9221.exe'
- '%TEMP%\ixp000.tmp\as0ce75.exe'
- '%TEMP%\ixp001.tmp\ar3mj83.exe'
- '%TEMP%\ixp002.tmp\sn2jt52.exe'
- '%TEMP%\ixp003.tmp\1py49yx4.exe'
- '%TEMP%\ixp003.tmp\3ib53ly.exe'
- '%TEMP%\ixp002.tmp\4is100yv.exe'
- '%TEMP%\3cb2.exe'
- '%APPDATA%\idfbwga'
- '%TEMP%\ixp000.tmp\as0ce75.exe' ' (with hidden window)
- '%TEMP%\ixp001.tmp\ar3mj83.exe' ' (with hidden window)
- '%TEMP%\ixp002.tmp\sn2jt52.exe' ' (with hidden window)
- '%TEMP%\ixp003.tmp\1py49yx4.exe' ' (with hidden window)
- '%TEMP%\ixp003.tmp\3ib53ly.exe' ' (with hidden window)
- '%TEMP%\ixp002.tmp\4is100yv.exe' ' (with hidden window)
- '%APPDATA%\idfbwga' ' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /f /RU "user" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 HR" /sc HOURLY /rl HIGHEST
- '<SYSTEM32>\svchost.exe' -k secsvcs
- '%WINDIR%\syswow64\schtasks.exe' /create /f /RU "user" /tr "%ALLUSERSPROFILE%\OfficeTrackerNMP131\OfficeTrackerNMP131.exe" /tn "OfficeTrackerNMP131 LG" /sc ONLOGON /rl HIGHEST
- '<SYSTEM32>\raserver.exe' /offerraupdate
- '<SYSTEM32>\taskeng.exe' {3332A608-E476-4EA5-83DF-785C26E0E3DD} S-1-5-21-3150914307-1777937420-491476919-1000:dubkgncifv\user:Interactive:[1]