Technical Information
- '%WINDIR%\syswow64\net.exe' stop foundation
- %ALLUSERSPROFILE%\nugets\template_41c318.tmptmpzip7
- '10#.#4.209.178':80
- http://10#.#4.209.178/02.dat
- '%WINDIR%\syswow64\net.exe' group /domain' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C net.exe stop foundation' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C sc delete foundation' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> >> NUL' (with hidden window)
- '%WINDIR%\syswow64\net.exe' group /domain
- '%WINDIR%\syswow64\net1.exe' group /domain
- '%WINDIR%\syswow64\cmd.exe' /C net.exe stop foundation
- '%WINDIR%\syswow64\cmd.exe' /C sc delete foundation
- '%WINDIR%\syswow64\sc.exe' delete foundation
- '%WINDIR%\syswow64\net1.exe' stop foundation
- '%WINDIR%\syswow64\cmd.exe' /c del <Full path to file> >> NUL