Technical Information
- User Account Control (UAC)
- '%WINDIR%\syswow64\taskkill.exe' /F /IM WmiPrvSE.exe
- %LOCALAPPDATA%\microsoft\windows\actioncentercache\windows-systemtoast-securityandmaintenance_10_0.png
- %HOMEPATH%\desktop\²éñ¯»úæ÷.cmd
- <Current directory>\ГЇВµГ³î¬»¤¹¤¾ß.exe
- %TEMP%\tmwork\wimlib-imagex.exe
- %TEMP%\tmwork\libwim-15.dll
- %TEMP%\tmwork\tmhook_v5.dll
- %TEMP%\tmwork\wallpaper.jpg
- %TEMP%\tmwork\litepe_deploy.exe
- %TEMP%\tmwork\litedownloader.exe
- %TEMP%\tmwork\todesk_lite.exe
- 'me##.668yun.top':443
- 'co########g-project.tos.coze.site':443
- 'st####.rapidssl.com':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9d##############
- http://st####.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRJiUKgT2m88fZ4nxc1Lu6M%2FjvkagQUDNtsgkkPSmcKuBTuesRIUojrVjgCEATGRzH8JzCsdrCWYvP5gIk%3D
- 'me##.668yun.top':443
- 'co########g-project.tos.coze.site':443
- DNS ASK me##.668yun.top
- DNS ASK co########g-project.tos.coze.site
- DNS ASK st####.rapidssl.com
- ClassName: 'ConsoleWindowClass' WindowName: ''
- ClassName: '' WindowName: ''
- '<Current directory>\ГЇВµГ³î¬»¤¹¤¾ß.exe'
- '%WINDIR%\syswow64\cmd.exe' /c powershell -command "Get-BitLockerVolume -MountPoint C | Select-Object -Property VolumeStatus"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "Get-BitLockerVolume -MountPoint C | Select-Object -Property VolumeStatus"
- '%WINDIR%\syswow64\cmd.exe' /c powershell -command "Get-BitLockerVolume -MountPoint D | Select-Object -Property VolumeStatus"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "Get-BitLockerVolume -MountPoint D | Select-Object -Property VolumeStatus"
- '%WINDIR%\syswow64\cmd.exe' /c ""%HOMEPATH%\Desktop\ÐÐЩÐâÐÐлÐÑÐâ з.cmd" "
- '%WINDIR%\syswow64\mode.com' con cols=90 lines=50
- '%WINDIR%\syswow64\cmd.exe' /c reg query "HKLM\HARDWARE\DESCRIPTION\System\BIOS" /v "SystemManufacturer"
- '%WINDIR%\syswow64\reg.exe' query "HKLM\HARDWARE\DESCRIPTION\System\BIOS" /v "SystemManufacturer"
- '%WINDIR%\syswow64\cmd.exe' /c reg query "HKLM\HARDWARE\DESCRIPTION\System\BIOS" /v "BaseBoardProduct"
- '%WINDIR%\syswow64\reg.exe' query "HKLM\HARDWARE\DESCRIPTION\System\BIOS" /v "BaseBoardProduct"
- '%WINDIR%\syswow64\cmd.exe' /c wmic cpu get name
- '%WINDIR%\syswow64\wbem\wmic.exe' cpu get name
- '%WINDIR%\syswow64\wbem\wmic.exe' csproduct get Name
- '%WINDIR%\syswow64\wbem\wmic.exe' cpu get serialnumber
- '%WINDIR%\syswow64\wbem\wmic.exe' bios get serialnumber
- '%WINDIR%\syswow64\wbem\wmic.exe' baseboard get serialnumber
- '%WINDIR%\syswow64\wbem\wmic.exe' csproduct get uuid
- '%WINDIR%\syswow64\wbem\wmic.exe' diskdrive get serialnumber
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /all|findstr /i "├Φ╩з ╬∩└φ╡╪╓╖"
- '%WINDIR%\syswow64\ipconfig.exe' /all
- '%WINDIR%\syswow64\findstr.exe' /i "├Φ╩з ╬∩└φ╡╪╓╖"