Technical Information
- '' (downloaded from the Internet)
- %TEMP%\winhost.exe
- %TEMP%\winhost.exe
- <Full path to file>
- 'wp#d':80
- 'dl.##anity.ru':80
- http://11#.#11.111.1/wpad.dat via wp#d
- http://dl.##anity.ru/api/winhost.exe
- DNS ASK wp#d
- DNS ASK dl.##anity.ru
- '%TEMP%\winhost.exe'
- '<SYSTEM32>\cmd.exe' /C ping 1.1.1.1 -n 1 -w 100 > Nul & Del "<Full path to file>"& ping 1.1.1.1 -n 1 -w 900 > Nul & Del "<Full path to file>"
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 100
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 900