Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\injector.vbs.vbs
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%WINDIR%\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSBUILD.EXE" "MSBUILD.EXE" ENABLE
- %WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe
- %TEMP%\injector.vbs.bin
- '18#.#89.112.142':5552
- '%WINDIR%\syswow64\regsvr32.exe' /I /S "%TEMP%\injector.vbs.BIN"' (with hidden window)
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%WINDIR%\MICROSOFT.NET\FRAMEWORK\V2.0.50727\MSBUILD.EXE" "MSBUILD.EXE" ENABLE' (with hidden window)
- '%WINDIR%\syswow64\wscript.exe' //b //e:vbscript "<PATH_SAMPLE>.vbs"
- '%WINDIR%\syswow64\regsvr32.exe' /I /S "%TEMP%\injector.vbs.BIN"
- '%WINDIR%\microsoft.net\framework\v2.0.50727\msbuild.exe'