Technical Information
- [HKLM\SYSTEM\CurrentControlSet\Services\21DF7FC0] 'ImagePath' = '<DRIVERS>\21DF7FC0.sys'
- '21DF7FC0' <DRIVERS>\21DF7FC0.sys
- 5f27d00f8e.exe process, ntdll.dll module
- <Current directory>\5f27d00f8e.exe
- <Current directory>\logs\overlay.log
- %TEMP%\deadstar\secureenginesdk64.dll
- %TEMP%\deadstar\vehhandler.dll
- <DRIVERS>\21df7fc0.sys
- %TEMP%\deadstar\vehhandler.dll
- %TEMP%\deadstar\secureenginesdk64.dll
- %TEMP%\deadstar\vehhandler.dll
- DNS ASK mo#####.map.fastly.net
- '<Current directory>\5f27d00f8e.exe' --deadstar-morphed
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "Wait-Process -Id 5572 -ErrorAction SilentlyContinue; Remove-Item -LiteralPath '<Full path to file>' -Force"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -WindowStyle Hidden -Command "Wait-Process -Id 5572 -ErrorAction SilentlyContinue; Remove-Item -LiteralPath '<Full path to file>' -Force"' (with hidden window)