Technical Information
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\bKnIDqiG.vbs"
- '%WINDIR%\explorer.exe' C:\Users\Public\bKnIDqiG.vbs
- C:\users\public\rfyxvdo.dat
- C:\users\public\bknidqig.vbs
- C:\users\public\bknidqig.vbs
- 'di###raft.in':443
- 'ht###kbrand.com':443
- 'wi###eaks.org':443
- DNS ASK di###raft.in
- DNS ASK ht###kbrand.com
- DNS ASK wi###eaks.org
- '%WINDIR%\explorer.exe' C:\Users\Public\bKnIDqiG.vbs' (with hidden window)
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\bKnIDqiG.vbs"' (with hidden window)