Technical Information
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\kPhzja.vbs"
- '%WINDIR%\explorer.exe' C:\Users\Public\kPhzja.vbs
- C:\users\public\vfqvau.dat
- C:\users\public\kphzja.vbs
- C:\users\public\a78dxzbo.html
- C:\users\public\kphzja.vbs
- 'di###raft.in':443
- 'ht###kbrand.com':443
- 'wi###eaks.org':443
- DNS ASK di###raft.in
- DNS ASK ht###kbrand.com
- DNS ASK wi###eaks.org
- '%WINDIR%\explorer.exe' C:\Users\Public\kPhzja.vbs' (with hidden window)
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\kPhzja.vbs"' (with hidden window)