Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'WindowsUpdate' = '<Full path to file>'
- <SYSTEM32>\tasks\windowsupdate
- %ALLUSERSPROFILE%\microsoft\windows\gamecache\system_log.txt
- %ALLUSERSPROFILE%\microsoft\windows\gamecache\login data
- %ALLUSERSPROFILE%\microsoft\windows\gamecache\passwords.txt
- 'di##ord.com':443
- 'cd#.#ixabay.com':443
- 'di##ord.com':443
- 'cd#.#ixabay.com':443
- DNS ASK di##ord.com
- DNS ASK cd#.#ixabay.com
- '<SYSTEM32>\cmd.exe' /c schtasks /create /tn "WindowsUpdate" /tr "<Full path to file>" /sc onlogon /f 2>nul
- '<SYSTEM32>\schtasks.exe' /create /tn "WindowsUpdate" /tr "<Full path to file>" /sc onlogon /f
- '<SYSTEM32>\cmd.exe' /c mkdir "%ALLUSERSPROFILE%\Microsoft\Windows\GameCache" 2>nul
- '<SYSTEM32>\rundll32.exe' <SYSTEM32>\FirewallControlPanel.dll,ShowNotificationDialog /configure /ETOnly 0 /OnProfiles 6 /OtherAllowed 0 /OtherBlocked 0 /OtherEdgeAllowed 0 /NewBlocked 4 "<Full path to file>"
- '<SYSTEM32>\cmd.exe' /c copy "%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data" "%ALLUSERSPROFILE%\Microsoft\Windows\GameCache\Login Data" 2>nul
- '<SYSTEM32>\cmd.exe' /c copy "%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data" "%ALLUSERSPROFILE%\Microsoft\Windows\GameCache\Login Data" 2>nul