Technical Information
- '<SYSTEM32>\taskkill.exe' /f /im explorer.exe
- %WINDIR%\explorer.exe
- <Current directory>\48896.bat
- <Current directory>\423426.txt
- <Current directory>\75820.bat
- <PATH_SAMPLE>5.exe
- <Current directory>\630544.txt
- <Current directory>\90492.bat
- <Current directory>\515573.txt
- <Current directory>\63655.bat
- <Current directory>\09047.txt
- <Current directory>\37719.txt
- <Current directory>\19518.bat
- <PATH_SAMPLE>3.exe
- <Current directory>\207046.bat
- <Current directory>\320318.txt
- <PATH_SAMPLE>7.exe
- <Current directory>\713000.txt
- <Current directory>\122402.bat
- <PATH_SAMPLE>0.exe
- <Current directory>\010615.txt
- <Current directory>\0.bat
- <PATH_SAMPLE>6.exe
- <Current directory>\65147.txt
- <Current directory>\67572.bat
- <PATH_SAMPLE>4.exe
- <Current directory>\421886.txt
- <Current directory>\27486.bat
- <Current directory>\71205.txt
- <SYSTEM32>\taskmgr.exe
- ClassName: '' WindowName: ''
- '<PATH_SAMPLE>4.exe' 1691717830
- '<PATH_SAMPLE>3.exe' /KillHardDisk 1691717830
- '<PATH_SAMPLE>3.exe' /killwindows 1691717830
- '<PATH_SAMPLE>7.exe' /autoup 1691717830
- '<PATH_SAMPLE>7.exe' /protect 1691717830
- '<PATH_SAMPLE>7.exe' /killMBR 1691717830
- '<PATH_SAMPLE>6.exe' /autoup 1691717830
- '<PATH_SAMPLE>0.exe' /autoup 1691717830
- '<PATH_SAMPLE>7.exe' /KillHardDisk 1691717830
- '<PATH_SAMPLE>6.exe' /protect 1691717830
- '<PATH_SAMPLE>0.exe' /protect 1691717830
- '<PATH_SAMPLE>7.exe' /killwindows 1691717830
- '<PATH_SAMPLE>6.exe' /killMBR 1691717830
- '<PATH_SAMPLE>0.exe' /killMBR 1691717830
- '<PATH_SAMPLE>6.exe' /KillHardDisk 1691717830
- '<PATH_SAMPLE>0.exe' /KillHardDisk 1691717830
- '<PATH_SAMPLE>6.exe' /killwindows 1691717830
- '<PATH_SAMPLE>0.exe' /killwindows 1691717830
- '<PATH_SAMPLE>4.exe' /autoup 1691717830
- '<PATH_SAMPLE>4.exe' /protect 1691717830
- '<PATH_SAMPLE>4.exe' /killMBR 1691717830
- '<PATH_SAMPLE>4.exe' /KillHardDisk 1691717830
- '<PATH_SAMPLE>4.exe' /killwindows 1691717830
- '<PATH_SAMPLE>5.exe' 1691717830
- '<PATH_SAMPLE>3.exe' 1691717830
- '<PATH_SAMPLE>7.exe' 1691717830
- '<PATH_SAMPLE>0.exe' 1691717830
- '<PATH_SAMPLE>6.exe' 1691717830
- '<PATH_SAMPLE>3.exe' /killMBR 1691717830
- '<PATH_SAMPLE>3.exe' /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /KillHardDisk 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /killMBR 1691717830
- '<SYSTEM32>\cmd.exe' /c del /f <SYSTEM32>\taskmgr.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /killMBR 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe /killwindows 1691717830
- '<SYSTEM32>\cmd.exe' /c takeown /f %WINDIR%\explorer.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe /KillHardDisk 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /autoup 1691717830
- '<SYSTEM32>\takeown.exe' /f %WINDIR%\explorer.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+37719.txt <PATH_SAMPLE>3.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /autoup 1691717830
- '<SYSTEM32>\cmd.exe' /c Cacls %WINDIR%\explorer.exe /t /e /c /guser:F
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe /protect 1691717830
- '<SYSTEM32>\cacls.exe' %WINDIR%\explorer.exe /t /e /c /guser:F
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe /autoup 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>3.exe /killwindows 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>3.exe /KillHardDisk 1691717830
- '<SYSTEM32>\cmd.exe' /c del C:\users /r /f
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>3.exe /killMBR 1691717830
- '<SYSTEM32>\cmd.exe' /c mountvol c: /d
- '<SYSTEM32>\cmd.exe' /c del /f %WINDIR%\explorer.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>3.exe /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe /killwindows 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /KillHardDisk 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe /killwindows 1691717830
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\taskmgr.exe /t /e /c /guser:F
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /autoup 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+421886.txt <PATH_SAMPLE>4.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+65147.txt <PATH_SAMPLE>6.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>6.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+010615.txt <PATH_SAMPLE>0.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>0.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+713000.txt <PATH_SAMPLE>7.exe
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im explorer.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /killwindows 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+320318.txt <PATH_SAMPLE>3.exe
- '<SYSTEM32>\mountvol.exe' c: /d
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>7.exe /killMBR 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>3.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+515573.txt <PATH_SAMPLE>5.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+630544.txt <PATH_SAMPLE>6.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>5.exe 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+423426.txt <PATH_SAMPLE>4.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /killwindows 1691717830
- '<SYSTEM32>\cmd.exe' /c takeown /f <SYSTEM32>\taskmgr.exe
- '<SYSTEM32>\takeown.exe' /f <SYSTEM32>\taskmgr.exe
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /KillHardDisk 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /killMBR 1691717830
- '<SYSTEM32>\cmd.exe' /c start <PATH_SAMPLE>4.exe /protect 1691717830
- '<SYSTEM32>\cmd.exe' /c Cacls <SYSTEM32>\taskmgr.exe /t /e /c /guser:F
- '<SYSTEM32>\cmd.exe' /c start <Full path to file> /save 1691717830
- '<SYSTEM32>\cmd.exe' /c copy /b <Full path to file>+09047.txt <PATH_SAMPLE>0.exe
- '<SYSTEM32>\cmd.exe' /c copy /b <PATH_SAMPLE>4.exe+71205.txt <PATH_SAMPLE>47.exe