Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\system.lnk
- %APPDATA%\sys64\mcbkcftjrsxkvk4tdfeg.exe
- %APPDATA%\sys64\5sxxl88irlazqkszr5kuemuvxwbbdf.vbs
- %APPDATA%\sys64\zwgwejbrkv7qw1oneqgh17dxfb2gh6.bat
- %APPDATA%\sys64\autopass.dll
- %APPDATA%\sys64\jpscauijqdxbfmag9upy92ogr0jw1t.bat
- %APPDATA%\sys64\sqlite.interop.dll
- %APPDATA%\sys64\vmcheck32.dll
- %APPDATA%\sys64\easyanticheat.exe
- %APPDATA%\sys64\system.vbe
- %APPDATA%\sys64\system.lnk
- 'ip##fo.io':80
- DNS ASK ip##fo.io
- DNS ASK ma####s.jhfree.net
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Sys64\5sXXl88IRLaZQKSzR5kUeMUVXWbBDf.vbs"
- '%APPDATA%\sys64\mcbkcftjrsxkvk4tdfeg.exe' -p1e1cd35deef407d5e04c46b4810b4d3c7ac55474
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Sys64\System.vbe"
- '%APPDATA%\sys64\easyanticheat.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Sys64\ZWGwejBrkv7Qw1oNeqGH17DXfb2gH6.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Sys64\JpsCAuIjQdxBfMaG9upY92Ogr0jw1T.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Sys64\ZWGwejBrkv7Qw1oNeqGH17DXfb2gH6.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""%APPDATA%\Sys64\JpsCAuIjQdxBfMaG9upY92Ogr0jw1T.bat" "