Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\WinDivert] 'ImagePath' = '%TEMP%\B16E.tmp\WinDivert64.sys'
- 'WinDivert' %TEMP%\B16E.tmp\WinDivert64.sys
- %TEMP%\b16e.tmp\b19e.tmp\b19f.bat
- %TEMP%\b16e.tmp\bypass.exe
- %TEMP%\b16e.tmp\cygwin1.dll
- %TEMP%\b16e.tmp\list-general.txt
- %TEMP%\b16e.tmp\quic_initial_www_google_com.bin
- %TEMP%\b16e.tmp\tls_clienthello_www_google_com.bin
- %TEMP%\b16e.tmp\windivert.dll
- %TEMP%\b16e.tmp\windivert64.sys
- %TEMP%\b16e.tmp\ipset-cloudflare.txt
- %TEMP%\b16e.tmp\ipset-discord.txt
- nul
- '78.#9.45.8':80
- http://78.#9.45.8/private-1.1.txt
- '%TEMP%\b16e.tmp\bypass.exe' --wf-tcp=80,443 --wf-udp=443,50000-50100 --filter-udp=443 --hostlist="%TEMP%\B16E.tmp/list-general.txt" --dpi-desync=fake --dpi-desync-repeats=12 --dpi-desync-fake-quic="%TEMP%\B16E.tmp/quic_in...
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\B16E.tmp\B19E.tmp\B19F.bat <Full path to file>"
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\net.exe' session
- '<SYSTEM32>\net1.exe' session
- '<SYSTEM32>\chcp.com' 1251
- '<SYSTEM32>\timeout.exe' /t 3 /nobreak
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Invoke-WebRequest -Uri http://78.#9.45.8/private-1.1.txt -UseBasicParsing"
- '<SYSTEM32>\findstr.exe' /i "true"
- '<SYSTEM32>\timeout.exe' /t 2 /nobreak
- '<SYSTEM32>\timeout.exe' /t 1 /nobreak