Technical Information
- '' (downloaded from the Internet)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- iexplore.exe
- iexplore.exe process, wininet.dll module
- firefox.exe process, nss3.dll module
- C:\users\public\vbc.exe
- %TEMP%\haxftkudj288ih
- %TEMP%\tvspnchovp
- %TEMP%\vcnxiravde.exe
- %TEMP%\vcnxiravde.exe
- '19#.#10.149.28':80
- '9i##6zm.cfd':80
- http://19#.#10.149.28/601/vbc.exe
- http://www.9i##6zm.cfd/an52/?on######################################################################################
- DNS ASK de####fenmif.club
- DNS ASK ta####arebel.com
- DNS ASK 9i##6zm.cfd
- DNS ASK cu#####dadesnews.online
- DNS ASK lb##110.com
- '%TEMP%\vcnxiravde.exe' %TEMP%\tvspnchovp
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\msdt.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\vcnxiravde.exe"