Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -inputformat none -outputformat none -NonInteractive -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\'
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-3150914307-1777937420-491476919-1000\83aa4cc77f591dfc2374580bbd95f6ba_d99ef00b-ccd3-4f1d-9980-90ac453b0b47
- %TEMP%\d95b7fa9bda2624b52feaff2ab1e914d.bat
- nul
- %TEMP%\culturemedianpro.zip
- %TEMP%\chromesetup.zip
- http://95.##4.87.58/fire/culturemedianpro.zip
- http://95.##4.87.58/fire/ChromeSetup.zip
- '%ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe' -Dfile.encoding=UTF-8 -classpath "<Full path to file>" org.develnext.jphp.ext.javafx.FXLauncher
- '<SYSTEM32>\cmd.exe' /c %TEMP%\d95b7fa9bda2624b52feaff2ab1e914d.bat
- '<SYSTEM32>\cmd.exe' /c "<SYSTEM32>\chcp.com 866>nul & <SYSTEM32>\wbem\wmic.exe OS get /Format:List | <SYSTEM32>\more.com"
- '<SYSTEM32>\chcp.com' 866
- '<SYSTEM32>\wbem\wmic.exe' OS get /Format:List
- '<SYSTEM32>\more.com'