Technical Information
- xoer.exe process, Amsi.dll module
- xoer.exe process, ntdll.dll module
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\<File name>.exe.log
- nul
- '17#.#68.136.38':8000
- '45.##.21.134':8000
- '45.##4.169.135':8000
- '21#.#32.69.52':8000
- '45.##4.168.55':8000
- '45.##4.169.172':8000
- '17#.#68.136.38':8000
- '45.##.21.134':8000
- '45.##4.169.135':8000
- '45.##4.168.55':8000
- '45.##4.169.172':8000
- '<SYSTEM32>\cmd.exe' /C timeout /t 4 /nobreak >nul & Del ""
- '<SYSTEM32>\timeout.exe' /t 4 /nobreak
- '<SYSTEM32>\cmd.exe' /C timeout /t 4 /nobreak >nul & Del ""' (with hidden window)