Technical Information
- %APPDATA%\host\host.exetext
- %APPDATA%\host\host.exe
- nul
- %APPDATA%\host\host.exe
- %APPDATA%\host\host.exetext
- 'microsoft.com':80
- DNS ASK microsoft.com
- '%APPDATA%\host\host.exe'
- '%WINDIR%\syswow64\certutil.exe' /decode "%APPDATA%\host\host.exetext" "%APPDATA%\host\host.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\certutil.exe' /decode "%APPDATA%\host\host.exetext" "%APPDATA%\host\host.exe"
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 1 -w 3000