Technical Information
- '' (downloaded from the Internet)
- 'C:\users\public\vbc.exe'
- C:\users\public\vbc.exe
- '19#.#10.240.37':80
- 'ab##ongo.cf':80
- http://19#.#10.240.37/g/pdp.exe
- http://ab##ongo.cf/g/Ilpzv_Tvynzfxj.png
- DNS ASK ab##ongo.cf
- '%WINDIR%\syswow64\cmd.exe' /C timeout /nobreak /t 19' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe' /C timeout /nobreak /t 19
- '%WINDIR%\syswow64\timeout.exe' /nobreak /t 19