Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'MSSMSGS' = 'rundll32.exe winlqj32.rom,XRhRun'
- iexplore.exe
- %TEMP%\tweffaf.tmp
- %WINDIR%\syswow64\winlqj32.rom
- %TEMP%\win9c3.tmp
- %TEMP%\tweffaf.bat
- <PATH_SAMPLE>.bat
- %TEMP%\tweffaf.tmp
- http://sm####security.biz/img/cmd.php?c=##########################################
- http://ww#.###rt-security.biz/
- DNS ASK se###hmeup.biz
- DNS ASK sm####security.biz
- DNS ASK ww#.###rt-security.biz
- ClassName: 'IEFrame' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\tweFFAF.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c "<PATH_SAMPLE>.bat"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c "%TEMP%\tweFFAF.bat"
- '%WINDIR%\syswow64\cmd.exe' /c "<PATH_SAMPLE>.bat"