Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /f -Im "<File name>.exe"
- %TEMP%\443h8ix8_.exe
- %TEMP%\luvz5.m
- %TEMP%\pvolk4u.rr
- %TEMP%\inhuzf3e.w1
- %TEMP%\osaxc5a.xbc
- %TEMP%\hyieku.s_
- nul
- %TEMP%\pvolk4u.rr
- %TEMP%\luvz5.m
- %TEMP%\inhuzf3e.w1
- %TEMP%\osaxc5a.xbc
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\443h8ix8_.exe' /pMcgNZDTmz7RDOfKwGuB2rwjNWbQA
- '%WINDIR%\syswow64\cmd.exe' /Q /C coPy /Y "<Full path to file>" 443H8ix8_.exe > NuL && StARt 443H8ix8_.exe /pMcgNZDTmz7RDOfKwGuB2rwjNWbQA & if "" == "" f...
- '%WINDIR%\syswow64\cmd.exe' /Q /C coPy /Y "%TEMP%\443H8ix8_.exe" 443H8ix8_.exe > NuL && StARt 443H8ix8_.exe /pMcgNZDTmz7RDOfKwGuB2rwjNWbQA & if "/pMcgNZDTmz7RDOf...
- '%WINDIR%\syswow64\cmd.exe' /Q /C EcHo | SEt /P = "MZ" > OSAxC5A.XBC & cOPY /B /y OSaXC5A.XBC + PVoLK4U.RR + LUVZ5.M + inHuZF3E.W1 hYIEKU.S_ ...
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" EcHo "
- '%WINDIR%\syswow64\cmd.exe' /S /D /c" SEt /P = "MZ" 1>OSAxC5A.XBC"
- '%WINDIR%\syswow64\regsvr32.exe' -u -S HYiEKU.S_