Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'ID_E2A96AA9' = 'wscript.exe //b %APPDATA%\Microsoft\Windows\CompPress\CompPress.vbs'
- <SYSTEM32>\tasks\id_e2a96aa9
- '<SYSTEM32>\wscript.exe' //b "%APPDATA%\gHjsfrf.vbs"
- %APPDATA%\ghjsfrf.vbs
- %APPDATA%\microsoft\windows\comppress\comppress.vbs
- %APPDATA%\ghjsfrf.vbs
- http://kr###in.website/vwasntvzioo_E2A96AA9/index_15_04.php
- DNS ASK kr###in.website
- '<SYSTEM32>\wscript.exe' //b "%APPDATA%\gHjsfrf.vbs"' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 13 /F /tn ID_E2A96AA9 /tr %APPDATA%\Microsoft\Windows\CompPress\CompPress.vbs' (with hidden window)
- '<SYSTEM32>\schtasks.exe' /Create /SC MINUTE /MO 13 /F /tn ID_E2A96AA9 /tr %APPDATA%\Microsoft\Windows\CompPress\CompPress.vbs