Technical Information
- %WINDIR%\tasks\ramez.job
- <SYSTEM32>\tasks\xf6mt1ntv
- %TEMP%\wzdghb4u.exe
- %TEMP%\sqfy36ac.exe
- %TEMP%\wrk05ftt.zip
- %TEMP%\ndy0xyei.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %TEMP%\d610cf342e\ramez.exe
- '18#.#56.72.96':80
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\wzdghb4u.exe'
- '%TEMP%\sqfy36ac.exe' x -aoa -bso0 -bsp1 "%TEMP%\wrK05FtT.zip" -p3pVA6kLv -o"%LOCALAPPDATA%\Temp"
- '%TEMP%\ndy0xyei.exe'
- '%TEMP%\d610cf342e\ramez.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\SQFy36aC.exe" x -aoa -bso0 -bsp1 "%TEMP%\wrK05FtT.zip" -p3pVA6kLv -o"%LOCALAPPDATA%\Temp""
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn "xF6Mt1nTv" /tr "%TEMP%\wzdghb4U.exe" /sc minute /mo 25 /ru "user" /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "xF6Mt1nTv" /tr "%TEMP%\wzdghb4U.exe" /sc minute /mo 25 /ru "user" /f
- '%TEMP%\ndy0xyei.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn "xF6Mt1nTv" /tr "%TEMP%\wzdghb4U.exe" /sc minute /mo 25 /ru "user" /f' (with hidden window)
- '%TEMP%\d610cf342e\ramez.exe' ' (with hidden window)