Technical Information
- '%WINDIR%\syswow64\taskkill.exe' /f -IM "<File name>.exe"
- %TEMP%\czxhz1d0sh.exe
- %TEMP%\5e7qvq.ew
- nul
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\czxhz1d0sh.exe' /PTK4z0X2dDKP
- '%WINDIR%\syswow64\cmd.exe' /c TyPE "<Full path to file>" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PTK4z0X2dDKP &iF "" =="" for %O iN ("<Full path to file>" ) do taskkill ...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c TyPE "%TEMP%\czXHZ1D0sh.exe" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PTK4z0X2dDKP &iF "/PTK4z0X2dDKP " =="" for %O iN ("%TEMP%\czXHZ1D0sh.exe" ) d...' (with hidden window)
- '%WINDIR%\syswow64\mshta.exe' VbsCrIPt: ClosE ( CreAteOBJECT ("wSCRiPT.sheLl" ). RUN ( "CMd /c TyPE ""<Full path to file>"" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PTK4...
- '%WINDIR%\syswow64\cmd.exe' /c TyPE "<Full path to file>" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PTK4z0X2dDKP &iF "" =="" for %O iN ("<Full path to file>" ) do taskkill ...
- '%WINDIR%\syswow64\mshta.exe' VbsCrIPt: ClosE ( CreAteOBJECT ("wSCRiPT.sheLl" ). RUN ( "CMd /c TyPE ""%TEMP%\czXHZ1D0sh.exe"" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PT...
- '%WINDIR%\syswow64\cmd.exe' /c TyPE "%TEMP%\czXHZ1D0sh.exe" >czXHZ1D0sh.exe&& sTart czXHZ1D0sh.exe /PTK4z0X2dDKP &iF "/PTK4z0X2dDKP " =="" for %O iN ("%TEMP%\czXHZ1D0sh.exe" ) d...
- '%WINDIR%\syswow64\regsvr32.exe' -s 5E7Qvq.EW -u