Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /im dfrgui.exe /f
- %TEMP%\dfrgui.exe
- %TEMP%\nsr7742.tmp
- %TEMP%\nsh7753.tmp\system.dll
- %TEMP%\7z
- %ALLUSERSPROFILE%\{euxd181o-4k5t-arjo-hocshd32sd5y}\mdm.exe
- %TEMP%\nsx255c.tmp
- %TEMP%\nsx255d.tmp\system.dll
- %TEMP%\dfrgui.exe
- DNS ASK ai###aftik.ru
- '%TEMP%\dfrgui.exe'
- '%ALLUSERSPROFILE%\{euxd181o-4k5t-arjo-hocshd32sd5y}\mdm.exe'
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}" /P "%USERNAME%:R"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}\mdm.exe" /P "%USERNAME%:R"' (with hidden window)
- '%ALLUSERSPROFILE%\{euxd181o-4k5t-arjo-hocshd32sd5y}\mdm.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\PP9S2G9PW3DY.ps1" /P "%USERNAME%:R"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\RP5WQ3N7GZ9D.vbs" /P "%USERNAME%:R"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\HVQ50RH3XJEA.cmd" /P "%USERNAME%:R"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}" /P "%USERNAME%:R"' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 30 /TN "84DR4R06IF22WF" /TR "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\RP5WQ3N7GZ9D.vbs" /F' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 15 /TN "1OAH2A5Q7V7MV0LVMS" /TR "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}\mdm.exe" /F' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im dfrgui.exe /f & erase ŒГ®XГ®\user\AppData\Local\Temp\dfrgui.exe & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}\mdm.exe" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" echo Y"
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}" /P "user:R"
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}\mdm.exe" /P "user:R"
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\PP9S2G9PW3DY.ps1" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\RP5WQ3N7GZ9D.vbs" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\HVQ50RH3XJEA.cmd" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\cmd.exe' /c echo Y|CACLS "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}" /P "%USERNAME%:R"
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 30 /TN "84DR4R06IF22WF" /TR "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\RP5WQ3N7GZ9D.vbs" /F
- '%WINDIR%\syswow64\schtasks.exe' /Create /SC MINUTE /MO 15 /TN "1OAH2A5Q7V7MV0LVMS" /TR "%ALLUSERSPROFILE%\{EUXD181O-4K5T-ARJO-HOCSHD32SD5Y}\mdm.exe" /F
- '%WINDIR%\syswow64\cmd.exe' /c taskkill /im dfrgui.exe /f & erase ŒГ®XГ®\user\AppData\Local\Temp\dfrgui.exe & exit
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\PP9S2G9PW3DY.ps1" /P "user:R"
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\HVQ50RH3XJEA.cmd" /P "user:R"
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}" /P "user:R"
- '%WINDIR%\syswow64\cacls.exe' "%ALLUSERSPROFILE%\{ZPEUS7XC-OTIZ-9YVW-D4VOTTSRCB59}\RP5WQ3N7GZ9D.vbs" /P "user:R"