Technical Information
- '%WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe'
- '<SYSTEM32>\ping.exe' 127.0.0.1
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 && move C:\8klpw8klpw\8klpw.vbs "%HOMEPATH%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8klpw.vbs"
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\vbc.exe
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- C:\8klpw8klpw\8klpw.exe
- C:\8klpw8klpw\8klpw.vbs
- %WINDIR%\Microsoft.NET\Framework\v2.0.50727\.Identifier
- DNS ASK sy####.duckdns.org
- ClassName: 'MS_WINHELP' WindowName: ''