Technical Information
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\HWg0y.vbs"
- '%WINDIR%\explorer.exe' C:\Users\Public\HWg0y.vbs
- C:\users\public\al03.dat
- C:\users\public\hwg0y.vbs
- C:\users\public\dsbyba.html
- C:\users\public\hwg0y.vbs
- C:\users\public\hwg0y.vbs
- 'ch###tian.bar':443
- DNS ASK ch###tian.bar
- '%WINDIR%\explorer.exe' C:\Users\Public\HWg0y.vbs' (with hidden window)
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\HWg0y.vbs"' (with hidden window)
- '<SYSTEM32>\wscript.exe' "C:\Users\Public\HWg0y.vbs"