Technical Information
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy unrestricted -Command "Add-MpPreference -ExclusionPath '<Current directory>\'"
- [HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- %HOMEPATH%\desktop\autoautokeoxe.lnk
- %WINDIR%\syswow64\windowspowershell\v1.0\config\tbroad.txt
- 'ca###rang.com':80
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- 'ut#####.colorado.edu':13
- 'ti##.ien.it':13
- 'ti##.nist.gov':13
- 'pt###me1.ptb.de':13
- 'fr##.##meanddate.com':80
- http://li#.##nhtrang.com/volamhoiucpk/version.txt
- http://fr##.##meanddate.com/clock/i3jl68nm/n246/tlir/tt0/tw0/tm3/th1
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK ca###rang.com
- DNS ASK li#.##nhtrang.com
- DNS ASK drive.google.com
- DNS ASK drive.usercontent.google.com
- DNS ASK ut#####.colorado.edu
- DNS ASK ti##.ien.it
- DNS ASK ti##.nist.gov
- DNS ASK pt###me1.ptb.de
- DNS ASK fr##.##meanddate.com
- ClassName: 'Sword3 Class' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /flushdns
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns