Adds a root certificate
Modifies value of AutoConfigURL parameter to 'https://thlbsd334huntrrr.onion.link/RM5w3Lf8.js?ip=95.211.190.199'
Modifies value of AutoConfigURL parameter to 'https://thlbsd334huntrrr.onion.link/oTOmECfW.js?ip=95.211.190.199'
Modifies value of AutoConfigURL parameter to 'https://thlbsd334huntrrr.onion.link/JB3HX5kw.js?ip=95.211.190.199'
Modifies value of AutoConfigURL parameter to 'https://thlbsd334huntrrr.onion.link/JnKmFcEQ.js?ip=95.211.190.199'
Modifies value of AutoConfigURL parameter to 'https://thlbsd334huntrrr.onion.link/dENJ9Zoc.js?ip=95.211.190.199'
Searches for the following windows
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
Creates and executes the following
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\RarSFX0\1XnE94pp879901.js"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ep Unrestricted -f "%TEMP%\H2vVwf12.ps1"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\27dqwCuU.ps1"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ep Unrestricted -f "%TEMP%\wtP92AmO.ps1"
- '%WINDIR%\syswow64\taskkill.exe' /F /im iexplore.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /F /im firefox.exe' (with hidden window)
- '%WINDIR%\syswow64\taskkill.exe' /F /im chrome.exe' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ep Unrestricted -f "%TEMP%\H2vVwf12.ps1"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\a4l25m1u.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCF70.tmp" "%TEMP%\CSCCF6F.tmp"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy Unrestricted -File "%TEMP%\27dqwCuU.ps1"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\z8ewptju.cmdline"' (with hidden window)
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2EDD.tmp" "%TEMP%\CSC2ECD.tmp"' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ep Unrestricted -f "%TEMP%\wtP92AmO.ps1"' (with hidden window)
Executes the following
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\a4l25m1u.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RESCF70.tmp" "%TEMP%\CSCCF6F.tmp"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\csc.exe' /noconfig /fullpaths @"%TEMP%\z8ewptju.cmdline"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\cvtres.exe' /NOLOGO /READONLY /MACHINE:IX86 "/OUT:%TEMP%\RES2EDD.tmp" "%TEMP%\CSC2ECD.tmp"