Technical Information
- '<SYSTEM32>\wscript.exe' "%APPDATA%\Microsoft\VBS1.vbs"
- %APPDATA%\Microsoft\VBS1.vbs
- C:\System32\<Virus name>.exe
- %APPDATA%\Microsoft\VBS1.vbs
- C:\System32\<Virus name>.exe
- from <Full path to virus> to %APPDATA%\<Virus name>.exe
- '<L###LNET>.0.2':0
- 'ml##.ac.cn':37561
- DNS ASK ml##.ac.cn
- ClassName: '#32770' WindowName: 'КУЖµФґ'
- ClassName: '#32770' WindowName: '??????'