Technical Information
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=ConfigStreamContainer_3860 dir=out action=allow program="%TEMP%\nsz7EA2.tmp\ConfigStreamContainer_3860.exe" enable=yes profile=public,private
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\nsz7ea2.tmp\nsexec.dll
- %TEMP%\nsz7ea2.tmp\basiccalculator1.exe
- %TEMP%\nsz7ea2.tmp\configstreamcontainer_3860.exe
- %TEMP%\nsz7ea2.tmp\configstreamcontainer_3860.exe.config
- %TEMP%\nsz7ea2.tmp\msedge.exe
- %TEMP%\nsz7ea2.tmp\selfdel.dll
- %TEMP%\nsz7ea2.tmp\basiccalculator1.exe
- %TEMP%\nsz7ea2.tmp\configstreamcontainer_3860.exe
- %TEMP%\nsz7ea2.tmp\configstreamcontainer_3860.exe.config
- %TEMP%\nsz7ea2.tmp\msedge.exe
- %TEMP%\nsz7ea2.tmp\nsexec.dll
- %TEMP%\nsz7ea2.tmp\selfdel.dll
- '%TEMP%\nsz7ea2.tmp\configstreamcontainer_3860.exe' "http://www.tetanusoveremphasize.click" "%TEMP%\nsz7EA2.tmp\8007"
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\netsh.exe' advfirewall firewall add rule name=ConfigStreamContainer_3860 dir=out action=allow program="%TEMP%\nsz7EA2.tmp\ConfigStreamContainer_3860.exe" enable=yes profile=public,private' (with hidden window)