Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\start.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %HOMEPATH%\start.vbs
- %HOMEPATH%\temp.bat
- %HOMEPATH%\hr_ubase.bat
- %HOMEPATH%\hr_ubase.ps1
- '87.##1.105.252':8808
- '%WINDIR%\syswow64\wscript.exe' "%HOMEPATH%\start.vbs"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -File "%HOMEPATH%\hr_ubase.ps1"
- '%WINDIR%\syswow64\cmd.exe' /c ""%HOMEPATH%\temp.bat" "
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('ZnVuY3Rpb24gRGVjb21wcmVzc0J5dGVzKCRjb21wcmVzc2VkRGF0YSkgeyAkbXMgPSBbSU8uTWVtb3J5U3RyZWFtXTo6bmV3KChbU3lzdGVt...
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%HOMEPATH%\temp.bat" "' (with hidden window)