Technical Information
- '' (downloaded from the Internet)
- '%APPDATA%\word.exe'
- %WINDIR%\explorer.exe
- firefox.exe
- %APPDATA%\word.exe
- %TEMP%\nsrc16c.tmp
- %TEMP%\vngqybrcgd.e
- %TEMP%\tjwcbu.exe
- %TEMP%\tjwcbu.exe
- 'ma##.####oflifeadventures.com':80
- http://ma##.####oflifeadventures.com/wp-content/plugins/70d5e28f51c1438d94e3e6dc84b95311/xt/mmd/shell/borilpokonta2.1.exe
- DNS ASK ma##.####oflifeadventures.com
- DNS ASK yq##ysy.com
- DNS ASK di#####indiatours.com
- DNS ASK fu##066.xyz
- '%TEMP%\tjwcbu.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\raserver.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\tjwcbu.exe"