Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\ms.onenote.lnk
- %TEMP%\ejtf.js
- 'public-trust.com':80
- 'fi####st.network':443
- 'drive.google.com':443
- 'gs##tic.com':443
- 'fo###.#oogleapis.com':443
- 'fo###.gstatic.com':443
- 'ss#.#static.com':443
- DNS ASK fi####st.network
- DNS ASK drive.google.com
- DNS ASK microsoft.com
- DNS ASK fo###.#oogleapis.com
- DNS ASK gs##tic.com
- DNS ASK fo###.gstatic.com
- DNS ASK ss#.#static.com
- DNS ASK public-trust.com
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'Static' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\ejtf.js" www.fi####st.network/ 1
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\ejtf.js" www.fi####st.network/ 2
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\ejtf.js" www.fi####st.network/ 1 & start /b wscript "%TEMP%\ejtf.js" www.fi####st.network/ 2' (with hidden window)
- '%WINDIR%\syswow64\explorer.exe' "https://drive.google.com/file/d/1rJVzRbvviUBfjGb4yqPqbUAWNlXcEZHE/view"
- '%WINDIR%\syswow64\cmd.exe' /c start /b wscript "%TEMP%\ejtf.js" www.fi####st.network/ 1 & start /b wscript "%TEMP%\ejtf.js" www.fi####st.network/ 2