Technical Information
- '' (downloaded from the Internet)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- <Current directory>\5d980000
- C:\users\public\vbc.exe
- <PATH_SAMPLE>.xlsx
- 'ho#.gl':80
- '21#.#14.52.113':80
- 'mi###ri365.net':80
- 'su####uniksure.com':80
- 'hi####ikerfab.com':80
- 'pl##fra.com':80
- 'd2##ip.com':80
- 'je###ash.com':80
- 'va####elimozin.com':80
- http://ho#.gl/?re###########
- http://www.ma####icosocial.com/qjnt/?TB#############################################################################
- DNS ASK ho#.gl
- DNS ASK mi###ri365.net
- DNS ASK su####uniksure.com
- DNS ASK hi####ikerfab.com
- DNS ASK pl##fra.com
- DNS ASK d2##ip.com
- DNS ASK ne#####andredsox.com
- DNS ASK ig##dnm.icu
- DNS ASK ma####icosocial.com
- DNS ASK je###ash.com
- DNS ASK va####elimozin.com
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\wscript.exe'
- '%WINDIR%\syswow64\cmd.exe' del "C:\Users\Public\vbc.exe"