Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\pp.vbs
- %WINDIR%\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe
- C:\users\public\nod.ps1
- 'wi#####.publicvm.com':5552
- DNS ASK wi#####.publicvm.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\nod.ps1"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -windo 1 -noexit -exec bypass -file "C:\Users\Public\nod.ps1"' (with hidden window)
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\pp.vbs"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\aspnet_compiler.exe'