Technical Information
- '' (downloaded from the Internet)
- '%APPDATA%\vbc.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe process, nss3.dll module
- %APPDATA%\vbc.exe
- %APPDATA%\microsoft\windows\cookies\user@google[1].txt
- %APPDATA%\vbc.exe
- http://ku#############dseverfortsdy4epidemicrgb.duckdns.org/kung2doc/winlog.exe
- DNS ASK ku#############dseverfortsdy4epidemicrgb.duckdns.org
- DNS ASK do#########ocs.googleusercontent.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmmon32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\vbc.exe"