Technical Information
- '<SYSTEM32>\wscript.exe' "%TEMP%\2fb888b6-0dcc-433e-a45f-e03690869195\1196438181.vbs"
- '%TEMP%\91db6816-61f0-460f-b633-6b691077ee06.exe'
- '%APPDATA%\WipeShadow.exe'
- '<SYSTEM32>\cmd.exe' /K "%APPDATA%\WipeShadow.exe"
- '<SYSTEM32>\reg.exe' reg add "HKLM\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "91db6816-61f0-460f-b633-6b691077ee06" /t REG_SZ /d "%APPDATA%\WipeShadow.exe" & exit
- WipeShadow.exe
- %APPDATA%\23EF5514-3059-436F-A4A7-4CEFAAB20EB1\run.dat
- %TEMP%\91db6816-61f0-460f-b633-6b691077ee06.exe
- %APPDATA%\WipeShadow.exe
- %TEMP%\2fb888b6-0dcc-433e-a45f-e03690869195\1196438181.vbs
- 'py##.#ublicvm.com':5182
- DNS ASK py##.#ublicvm.com