Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\system.lnk
- <SYSTEM32>\tasks\348283fe091beb73890fa1cbebf1bc52
- C:\steamdriver\q354q5bmqpshq6x5t026.exe
- C:\steamdriver\2y1nnn8wbxh1lg0gx3zopkrad2kzp7.vbs
- C:\steamdriver\rvvfzm57izomketwvez4pptb3eewcv.bat
- C:\steamdriver\gueqrf90dgg8mrmq76ugpwqeh2xbxx.bat
- C:\steamdriver\vmcheck32.dll
- C:\steamdriver\chrome.exe
- C:\steamdriver\system.vbe
- C:\steamdriver\system.lnk
- http://a0####23.xsph.ru/ksl7b8oclevv7sqcj2akngf07/6lglj2clwzu98u4qp01d5pn9yc90547js/901212b6cc3a718fd6012ed1ff31c04663ffeb8b.php?f2################################
- http://a0####23.xsph.ru/ksl7b8oclevv7sqcj2akngf07/6lglj2clwzu98u4qp01d5pn9yc90547js/901212b6cc3a718fd6012ed1ff31c04663ffeb8b.php?aa##############################################################...
- http://a0####23.xsph.ru/ksl7b8oclevv7sqcj2akngf07/6lglj2clwzu98u4qp01d5pn9yc90547js/slyatds1jm26qhd8uc7nyr8bmqkygefjptw78el75w7y4icwuahv8un24hc4f8pn1gfc3gaudns57xkdj5ta930x5/040d63f89f19ce86d46...
- http://ip##fo.io/ip
- DNS ASK a0####23.xsph.ru
- DNS ASK ip##fo.io
- ClassName: 'EDIT' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "C:\steamdriver\2Y1nnN8WBxH1lg0gx3zoPkrAD2KZP7.vbs"
- 'C:\steamdriver\q354q5bmqpshq6x5t026.exe' -pa02c339505b1d1eee8718c63f82a5d1a1cbb3d31
- '%WINDIR%\syswow64\wscript.exe' "C:\steamdriver\System.vbe"
- 'C:\steamdriver\chrome.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\steamdriver\rvvFzM57IZomkETWvEZ4pPTB3eEwCv.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\steamdriver\GUEqrF90dgG8mRmQ76uGPWqeh2Xbxx.bat" "' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\steamdriver\rvvFzM57IZomkETWvEZ4pPTB3eEwCv.bat" "
- '%WINDIR%\syswow64\cmd.exe' /c ""C:\steamdriver\GUEqrF90dgG8mRmQ76uGPWqeh2Xbxx.bat" "