Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.lnk
- %APPDATA%\microsoft\security\<File name>.exe
- %TEMP%\tmp6622.vbs
- %TEMP%\tmp6622.vbs
- 'ap#.vk.com':443
- 'im.#k.com':443
- DNS ASK ap#.vk.com
- DNS ASK im.#k.com
- '%APPDATA%\microsoft\security\<File name>.exe'
- '<SYSTEM32>\wscript.exe' "%TEMP%\tmp6622.vbs" "%APPDATA%\Microsoft\Security\<File name>.exe" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\<File name>.lnk"
- '<SYSTEM32>\cmd.exe' /s /k WScript "%TEMP%\tmp6622.vbs" "%APPDATA%\Microsoft\Security\<File name>.exe" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\<File name>.lnk" & del /q "%TEMP%\tmp6622.vbs" & exit