Technical Information
- msbuild.exe
- %TEMP%\advancedrun.exe
- %TEMP%\msbuild.exe
- %TEMP%\advancedrun.exe
- 'ch####p.dyndns.org':80
- 'fr###eoip.app':443
- http://ch####p.dyndns.org/
- 'fr###eoip.app':443
- DNS ASK ch####p.dyndns.org
- DNS ASK fr###eoip.app
- '%TEMP%\advancedrun.exe' /EXEFilename "<SYSTEM32>\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run
- '%TEMP%\advancedrun.exe' /SpecialRun 4101d8 3160
- '%TEMP%\advancedrun.exe' /EXEFilename "<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe" /WindowState 0 /CommandLine "rmdir '%ALLUSERSPROFILE%\Microsoft\Windows Defender' -Recurse" /StartDirectory "" /RunAs 8 /Run
- '%TEMP%\advancedrun.exe' /SpecialRun 4101d8 2908
- '%TEMP%\msbuild.exe'