Technical Information
- '' (downloaded from the Internet)
- C:\AUTOEXEC.BAT.exe
- <Full path to file>.exe
- C:\DbgLog.log.exe
- %TEMP%\7zs.sfx
- %TEMP%\7za.exe
- %TEMP%\setup.exe
- <Full path to file>
- 'qu##ta.tk':80
- http://qu##ta.tk/7z/setup.exe
- http://qu##ta.tk/7z/7za.exe
- http://qu##ta.tk/7z/7zs.sfx
- DNS ASK qu##ta.tk
- '%TEMP%\7za.exe' a -t7z %TEMP%\installer.7z %TEMP%\setup.exe c:\DbgLog.log
- '%TEMP%\7za.exe' a -t7z %TEMP%\installer.7z %TEMP%\setup.exe <Full path to file>
- '%TEMP%\7za.exe' a -t7z %TEMP%\installer.7z %TEMP%\setup.exe c:\AUTOEXEC.BAT
- '<SYSTEM32>\cmd.exe' /c copy /b %TEMP%\7zs.sfx + %TEMP%\config.txt + %TEMP%\installer.7z c:\DbgLog.log.exe
- '<SYSTEM32>\cmd.exe' /c copy /b %TEMP%\7zs.sfx + %TEMP%\config.txt + %TEMP%\installer.7z <Full path to file>.exe
- '<SYSTEM32>\cmd.exe' /c copy /b %TEMP%\7zs.sfx + %TEMP%\config.txt + %TEMP%\installer.7z c:\AUTOEXEC.BAT.exe