Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'STARTUP' = 'C:\GatonFiles\Scirpts\Actualizador.vbs'
- C:\gatonfiles\scirpts\regedit.vbs
- C:\temp\files\cmc.bat
- C:\temp\files\despiertador.bat
- C:\temp\files\despiertador.vbs
- C:\temp\files\files.vbs
- C:\temp\files\messagesender.vbs
- C:\temp\files\regedit.vbs
- C:\temp\files\wifi.bat
- C:\gatonfiles\scirpts\despiertador.bat
- C:\temp\files\despiertadorrapido.vbs
- C:\temp\files\despiertadorrapido.bat
- C:\temp\files\despiertadespiertador.vbs
- C:\temp\files\despiertadespiertador.bat
- C:\temp\files\actualizador.vbs
- C:\temp\files\link.exe
- C:\gatonfiles\scirpts\mortu.bat
- C:\gatonfiles\scirpts\morto.bat
- C:\gatonfiles\scirpts\actualizador.vbs
- C:\gatonfiles\scirpts\uploader.vbs
- C:\gatonfiles\scirpts\despiertadespiertador.vbs
- C:\gatonfiles\scirpts\despiertadespiertador.bat
- C:\gatonfiles\scirpts\despiertadorrapido.vbs
- C:\gatonfiles\scirpts\despiertador.vbs
- C:\gatonfiles\scirpts\cmc.bat
- C:\temp\files\userdata.bat
- C:\gatonfiles\scirpts\wifi.bat
- C:\gatonfiles\scirpts\link.exe
- C:\gatonfiles\scirpts\files.vbs
- C:\gatonfiles\scirpts\despiertadorrapido.bat
- C:\gatonfiles\scirpts\userdata.bat
- C:\gatonfiles\scirpts\messagesender.vbs
- C:\gatonfiles\scirpts\uploader.bat
- C:\temp\files\uploader.bat
- C:\temp\files\uploader.vbs
- C:\gatonfiles\scirpts\regedit.vbs
- C:\gatonfiles\scirpts\actualizador.vbs
- C:\gatonfiles\scirpts\uploader.vbs
- C:\gatonfiles\scirpts\despiertadespiertador.vbs
- C:\gatonfiles\scirpts\despiertadespiertador.bat
- C:\gatonfiles\scirpts\despiertadorrapido.vbs
- C:\gatonfiles\scirpts\despiertador.vbs
- C:\gatonfiles\scirpts\cmc.bat
- C:\gatonfiles\scirpts\despiertador.bat
- C:\gatonfiles\scirpts\wifi.bat
- C:\gatonfiles\scirpts\link.exe
- C:\gatonfiles\scirpts\files.vbs
- C:\gatonfiles\scirpts\despiertadorrapido.bat
- C:\gatonfiles\scirpts\userdata.bat
- C:\gatonfiles\scirpts\messagesender.vbs
- C:\gatonfiles\scirpts\uploader.bat
- C:\gatonfiles\scirpts\morto.bat
- C:\gatonfiles\scirpts\mortu.bat
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK cd#.##scordapp.com
- DNS ASK microsoft.com
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\DespiertadorRapido.vbs"
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\Files.vbs"
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\Messagesender.vbs"
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\Regedit.vbs"
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\DespiertaDespiertador.vbs"
- '<SYSTEM32>\wscript.exe' "C:\GatonFiles\Scirpts\Despiertador.vbs" param1
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\cmc.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\DespiertaDespiertador.bat" "' (with hidden window)
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v reco /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\UserData.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\Uploader.bat" "' (with hidden window)
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v fea /f"' (with hidden window)
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v nes /f"' (with hidden window)
- '<SYSTEM32>\ping.exe' -n 1 -w 300 1.1.1.1' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\DespiertadorRapido.bat" "' (with hidden window)
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v STARTUP /d "C:\GatonFiles\Scirpts\Actualizador.vbs" /f"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\Despiertador.bat" "' (with hidden window)
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\cmd.exe' /c wmic cpu get NumberOfCores
- '<SYSTEM32>\wbem\wmic.exe' process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Files.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine,ProcessId /format:value
- '<SYSTEM32>\wbem\wmic.exe' cpu get NumberOfCores
- '<SYSTEM32>\timeout.exe' /t 5 /NOBREAK
- '<SYSTEM32>\timeout.exe' /t 3 /Nobreak
- '<SYSTEM32>\cmd.exe' /c wmic path win32_VideoController get name
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get name
- '<SYSTEM32>\cmd.exe' /c wmic path win32_VideoController get CurrentRefreshRate
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get CurrentRefreshRate
- '<SYSTEM32>\cmd.exe' /c wmic path win32_VideoController get DriverVersion
- '<SYSTEM32>\wbem\wmic.exe' process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Messagesender.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine,ProcessId /format:value
- '<SYSTEM32>\cmd.exe' /c wmic process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Files.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine,ProcessId /format:value
- '<SYSTEM32>\timeout.exe' 5
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get VideoModeDescription
- '<SYSTEM32>\cmd.exe' /c wmic baseboard get product
- '<SYSTEM32>\wbem\wmic.exe' baseboard get product
- '<SYSTEM32>\cmd.exe' /c wmic OS GET Caption
- '<SYSTEM32>\wbem\wmic.exe' OS GET Caption
- '<SYSTEM32>\cmd.exe' /c wmic OS GET CSName
- '<SYSTEM32>\wbem\wmic.exe' OS GET CSName
- '<SYSTEM32>\timeout.exe' /t 10 /NOBREAK
- '<SYSTEM32>\cmd.exe' /c wmic OS GET Version
- '<SYSTEM32>\wbem\wmic.exe' OS GET Version
- '<SYSTEM32>\wbem\wmic.exe' path win32_VideoController get DriverVersion
- '<SYSTEM32>\cmd.exe' /c wmic path win32_VideoController get VideoModeDescription
- '<SYSTEM32>\cmd.exe' /c wmic process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Messagesender.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine,ProcessId /format:value
- '<SYSTEM32>\wbem\wmic.exe' cpu get CurrentClockSpeed
- '<SYSTEM32>\cmd.exe' /c wmic cpu get CurrentClockSpeed
- '<SYSTEM32>\cmd.exe' /c wmic process where "name='wscript.exe'" get ParentProcessID
- '<SYSTEM32>\wbem\wmic.exe' process where "name='wscript.exe'" get ParentProcessID
- '<SYSTEM32>\timeout.exe' 1 /nobreak
- '<SYSTEM32>\ping.exe' -n 1 -w 300 1.1.1.1
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\Uploader.bat" "
- '<SYSTEM32>\timeout.exe' 3 /nobreak
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v fea /f"
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v nes /f"
- '<SYSTEM32>\reg.exe' delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v reco /f"
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\UserData.bat" "
- '<SYSTEM32>\timeout.exe' 1
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\DespiertadorRapido.bat" "
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v STARTUP /d "C:\GatonFiles\Scirpts\Actualizador.vbs" /f"
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\DespiertaDespiertador.bat" "
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\cmc.bat" "
- '<SYSTEM32>\cmd.exe' /c wmic process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Despiertador.bat%" and not CommandLine like "%RuntimeBroker%"' get CommandLine , ProcessId / format:value
- '<SYSTEM32>\wbem\wmic.exe' process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Despiertador.bat%" and not CommandLine like "%RuntimeBroker%"' get CommandLine , ProcessId / format:value
- '<SYSTEM32>\netsh.exe' wlan show profiles
- '<SYSTEM32>\findstr.exe' /R /C:"[ ]:[ ]"
- '<SYSTEM32>\cmd.exe' /c wmic cpu get name
- '<SYSTEM32>\wbem\wmic.exe' cpu get name
- '<SYSTEM32>\cmd.exe' /c ""C:\GatonFiles\Scirpts\Despiertador.bat" "
- '<SYSTEM32>\cmd.exe' /c wmic process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Regedit.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine , ProcessId / format:value
- '<SYSTEM32>\wbem\wmic.exe' process where 'CommandLine like "%C:\\GatonFiles\\Scirpts\\Regedit.vbs%" and not CommandLine like "%RuntimeBroker%"' get CommandLine , ProcessId / format:value
- '<SYSTEM32>\cmd.exe' /c curl "https://myexternalip.com/raw"
- '<SYSTEM32>\cmd.exe' /c wmic OS GET OSArchitecture
- '<SYSTEM32>\wbem\wmic.exe' OS GET OSArchitecture