Technical Information
- %TEMP%\df3b1027b018241e0ccd09ffd77695a0.exe
- %TEMP%\f33fed96f6902646ea61b4cc458a6bf3.vbs
- %TEMP%\df3b1027b018241e0ccd09ffd77695a0.exe
- %TEMP%\f33fed96f6902646ea61b4cc458a6bf3.vbs
- <Full path to file>
- 'ge##ekt.xyz':80
- http://ge##ekt.xyz/api/update.php
- DNS ASK ge##ekt.xyz
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\F33FED96F6902646EA61B4CC458A6BF3.vbs"