Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %TEMP%\dynwrapx.dll
- '14#.#5.84.40':4070
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- '14#.#5.84.40':4070
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\regsvr32.exe' /I /S %TEMP%\dynwrapx.dll' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' //b //e:vbscript "<PATH_SAMPLE>.vbs"
- '%WINDIR%\syswow64\regsvr32.exe' /I /S %TEMP%\dynwrapx.dll
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'