Technical Information
- %TEMP%\opbmifsuzo_signer.bat
- nul
- %APPDATA%\microsoft\crypto\keys\d4ab916f05b44e5ef422a54e36f83eed_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %APPDATA%\microsoft\systemcertificates\request\certificates\e09c44afdf2c796083f6355d3bcc469cc184b03e
- %APPDATA%\microsoft\systemcertificates\my\certificates\f67e8737f34ae073b8f56458d13503bae2e081a3
- %APPDATA%\microsoft\systemcertificates\my\keys\73d97a6b0577c7fc4da746e8773262c4255fa56a
- %TEMP%\temp_cert.cer
- %APPDATA%\microsoft\systemcertificates\request\certificates\e09c44afdf2c796083f6355d3bcc469cc184b03e
- %TEMP%\temp_cert.cer
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\opbMifsUZO_signer.bat" "
- '<SYSTEM32>\timeout.exe' /t 1 /nobreak
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -Command "$cert = New-SelfSignedCertificate -Type CodeSigningCert -Subject 'CN=ZUywKXKRdV' -CertStoreLocation Cert:\CurrentUser\My -NotAfter (Get-Date).AddYears(1); $cer...
- '<SYSTEM32>\svchost.exe' -k LocalSystemNetworkRestricted -p -s NgcSvc
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\opbMifsUZO_signer.bat" "' (with hidden window)