Technical Information
- %WINDIR%\tasks\ramez.job
- <SYSTEM32>\tasks\kndszun3h
- %TEMP%\1zieftsk.exe
- %TEMP%\gpkehl4m.exe
- %TEMP%\i1seresd.zip
- %TEMP%\rhqegh0g.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- %TEMP%\d610cf342e\ramez.exe
- '18#.#56.72.96':80
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\1zieftsk.exe'
- '%TEMP%\gpkehl4m.exe' x -aoa -bso0 -bsp1 "%TEMP%\I1SereSd.zip" -pLNbPunID -o"%LOCALAPPDATA%\Temp"
- '%TEMP%\rhqegh0g.exe'
- '%TEMP%\d610cf342e\ramez.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\gpkehl4M.exe" x -aoa -bso0 -bsp1 "%TEMP%\I1SereSd.zip" -pLNbPunID -o"%LOCALAPPDATA%\Temp""
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn "KndsZUN3h" /tr "%TEMP%\1ZIeftsk.exe" /sc minute /mo 25 /ru "user" /f
- '%WINDIR%\syswow64\schtasks.exe' /create /tn "KndsZUN3h" /tr "%TEMP%\1ZIeftsk.exe" /sc minute /mo 25 /ru "user" /f
- '%TEMP%\rhqegh0g.exe' ' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /tn "KndsZUN3h" /tr "%TEMP%\1ZIeftsk.exe" /sc minute /mo 25 /ru "user" /f' (with hidden window)
- '%TEMP%\d610cf342e\ramez.exe' ' (with hidden window)