Technical Information
- '%WINDIR%\syswow64\taskkill.exe' -F /IM "<File name>.exe"
- %TEMP%\syrbo.exe
- %TEMP%\jbycxf.7~
- nul
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\syrbo.exe' /pcofWrgNLX5ZwTAhgHjbH_V28
- '%WINDIR%\syswow64\cmd.exe' /q /c COPY /Y "<Full path to file>" sYRBo.exe > nuL && starT sYRBo.exe /pcofWrgNLX5ZwTAhgHjbH_V28 & IF "" =="" for %k in ( ...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /q /c COPY /Y "%TEMP%\sYRBo.exe" sYRBo.exe > nuL && starT sYRBo.exe /pcofWrgNLX5ZwTAhgHjbH_V28 & IF "/pcofWrgNLX5ZwTAhgHjbH_V28 " =="" fo...' (with hidden window)
- '%WINDIR%\syswow64\mshta.exe' vbsCripT: cloSE(cReATEoBjeCT ("WscRiPt.sHelL"). RUN( "cmd.ExE /q /c COPY /Y ""<Full path to file>"" sYRBo.exe > nuL && ...
- '%WINDIR%\syswow64\cmd.exe' /q /c COPY /Y "<Full path to file>" sYRBo.exe > nuL && starT sYRBo.exe /pcofWrgNLX5ZwTAhgHjbH_V28 & IF "" =="" for %k in ( ...
- '%WINDIR%\syswow64\mshta.exe' vbsCripT: cloSE(cReATEoBjeCT ("WscRiPt.sHelL"). RUN( "cmd.ExE /q /c COPY /Y ""%TEMP%\sYRBo.exe"" sYRBo.exe > nuL && s...
- '%WINDIR%\syswow64\cmd.exe' /q /c COPY /Y "%TEMP%\sYRBo.exe" sYRBo.exe > nuL && starT sYRBo.exe /pcofWrgNLX5ZwTAhgHjbH_V28 & IF "/pcofWrgNLX5ZwTAhgHjbH_V28 " =="" fo...
- '%WINDIR%\syswow64\regsvr32.exe' -U .\JBYCXF.7~ /s