Technical Information
- '<SYSTEM32>\taskkill.exe' /FI "IMAGENAME eq fiddler*" /IM * /F /T
- '<SYSTEM32>\taskkill.exe' /FI "IMAGENAME eq wireshark*" /IM * /F /T
- '<SYSTEM32>\taskkill.exe' /FI "IMAGENAME eq httpdebugger*" /IM * /F /T
- nul
- from <Full path to file> to <Current directory>\securityp-e4w0vmh5y9gd.exe
- 'localhost':49182
- 'localhost':49184
- 'ke##uth.win':443
- 'localhost':49182
- 'localhost':49184
- 'localhost':49185
- 'ke##uth.win':443
- DNS ASK ke##uth.win
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c taskkill /FI "IMAGENAME eq fiddler*" /IM * /F /T >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c taskkill /FI "IMAGENAME eq wireshark*" /IM * /F /T >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c taskkill /FI "IMAGENAME eq httpdebugger*" /IM * /F /T >nul 2>&1
- '<SYSTEM32>\cmd.exe' /c sc stop HTTPDebuggerPro >nul 2>&1
- '<SYSTEM32>\sc.exe' stop HTTPDebuggerPro
- '<SYSTEM32>\cmd.exe' /c sc stop HTTPDebuggerProSdk >nul 2>&1
- '<SYSTEM32>\sc.exe' stop HTTPDebuggerProSdk
- '<SYSTEM32>\cmd.exe' /c @RD /S /Q "C:\Users\%username%\AppData\Local\Microsoft\Windows\<INETFILES>\IE" >nul 2>&1