Adds a root certificate
Modifies value of AutoConfigURL parameter to 'https://p3efippdsssrqxbx.onion.to/jIlde0c4.js?ip=95.211.190.198'
Modifies value of AutoConfigURL parameter to 'https://p3efippdsssrqxbx.onion.to/DveuVpNn.js?ip=95.211.190.198'
Modifies value of AutoConfigURL parameter to 'https://p3efippdsssrqxbx.onion.to/ktapifvV.js?ip=95.211.190.198'
Modifies value of AutoConfigURL parameter to 'https://p3efippdsssrqxbx.onion.to/9MEyPBKg.js?ip=95.211.190.198'
Modifies value of AutoConfigURL parameter to 'https://p3efippdsssrqxbx.onion.to/ORb1N0Ph.js?ip=95.211.190.198'
Searches for the following windows
- ClassName: '' WindowName: ''
Creates and executes the following
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\8GAayv19.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\q80lbwFe.ps1"
- '<SYSTEM32>\taskkill.exe' /F /im iexplore.exe' (with hidden window)
- '<SYSTEM32>\taskkill.exe' /F /im firefox.exe' (with hidden window)
- '<SYSTEM32>\taskkill.exe' /F /im chrome.exe' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\8GAayv19.ps1"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\gtdkuon9.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F7F.tmp" "%TEMP%\CSC9F6E.tmp"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\q80lbwFe.ps1"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\swld1kqc.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES657.tmp" "%TEMP%\CSC637.tmp"' (with hidden window)
Executes the following
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\gtdkuon9.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES9F7F.tmp" "%TEMP%\CSC9F6E.tmp"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\swld1kqc.cmdline"
- '%WINDIR%\microsoft.net\framework64\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES657.tmp" "%TEMP%\CSC637.tmp"