Technical Information
- '<SYSTEM32>\taskkill.exe' /f /im wscript.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe
- C:\temp\ps_md1y5hq7nxlb_1781657189498.ps1
- %ALLUSERSPROFILE%\remcos\logs.dat
- C:\temp\ps_md1y5hq7nxlb_1781657189498.ps1
- DNS ASK br######oughgee.ddns.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -File "C:\Temp\ps_mD1Y5hQ7nXlB_1781657189498.ps1"
- '%WINDIR%\microsoft.net\framework\v4.0.30319\aspnet_compiler.exe'
- '<SYSTEM32>\taskkill.exe' /f /im wscript.exe' (with hidden window)