Analyse of the backdoored file
Hi i am new here this is my first contribution.
First of all this is backdoored it drops a the bin on : C:/Users/xxxxxx/AppData/Roaming/WinDefender/windefender.exe
It also drop some files on %TEMP%
The cc.vbs add windefender.exe to startup.
The server inject...