Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '-1-5-21-1960123792-202' = '%LOCALAPPDATA%\z_user\user.vbs'
- %APPDATA%\microsoft\windows\start menu\programs\startup\20193.exe
- <SYSTEM32>\tasks\maintenance
- %WINDIR%\syswow64\ehstorauthn.exe
- %LOCALAPPDATA%\z_user\wallpaper.mp4
- %LOCALAPPDATA%\z_user\user.vbs
- %LOCALAPPDATA%\z_user\user.bat
- %APPDATA%\del.bat
- %APPDATA%\microsoft\windows\start menu\programs\startup\20193.exe
- 'sm##021.net':80
- http://sm##021.net/wp-adm/gate.php
- DNS ASK sm##021.net
- '%APPDATA%\microsoft\windows\start menu\programs\startup\20193.exe'
- '%APPDATA%\microsoft\windows\start menu\programs\startup\20193.exe' ' (with hidden window)
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 5 /tn "Maintenance" /tr "C:\Users\%USERNAME%\AppData\Local\z_%USERNAME%\%USERNAME%.vbs" /F' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %APPDATA%\del.bat
- '%WINDIR%\syswow64\ping.exe' localhost -n 3
- '%WINDIR%\syswow64\cmd.exe' /c del "%APPDATA%\del.bat"
- '%WINDIR%\syswow64\ehstorauthn.exe'
- '%WINDIR%\syswow64\schtasks.exe' /create /sc minute /mo 5 /tn "Maintenance" /tr "C:\Users\%USERNAME%\AppData\Local\z_%USERNAME%\%USERNAME%.vbs" /F