Technical Information
- <SYSTEM32>\tasks\internet explorer
- Windows Defender
- internet explorer.exe
- %APPDATA%\internet explorer\internet explorer.exe
- %APPDATA%\logs\04-24-2021
- %TEMP%\gucdoazyxh6b.bat
- nul
- %TEMP%\bkibtxsrbgpk.bat
- 'ip##pi.com':80
- 'pa########oison.000webhostapp.com':443
- '91.##4.207.16':80
- 'pa########oison.000webhostapp.com':443
- DNS ASK ip##pi.com
- DNS ASK pa########oison.000webhostapp.com
- DNS ASK ip####bt.hopto.org
- '%APPDATA%\internet explorer\internet explorer.exe'
- '%WINDIR%\syswow64\cmd.exe' /k start /b del /q/f/s %TEMP%\* & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\GuCdOAZyXh6B.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\bkiBTXSRbGpk.bat" "' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Internet Explorer" /sc ONLOGON /tr "<Full path to file>" /rl HIGHEST /f
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Get-MpPreference -verbose
- '%WINDIR%\syswow64\cmd.exe' /k start /b del /q/f/s %TEMP%\* & exit
- '%WINDIR%\syswow64\cmd.exe' /K del /q/f/s %TEMP%\*
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "Internet Explorer" /sc ONLOGON /tr "%APPDATA%\Internet Explorer\Internet Explorer.exe" /rl HIGHEST /f
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\GuCdOAZyXh6B.bat" "
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\ping.exe' -n 10 localhost
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\bkiBTXSRbGpk.bat" "