Technical Information
- %WINDIR%\syswow64\cmd.exe
- %TEMP%\aut925e.tmp
- %TEMP%\aupair_7f155fe43f519ab3a6bb116265f90877.jpg
- %TEMP%\aut926f.tmp
- %TEMP%\1.exe
- %TEMP%\aut925e.tmp
- %TEMP%\aut926f.tmp
- http://www.ar###haring.com/do.php?do#########
- DNS ASK ar###haring.com
- '%TEMP%\1.exe'
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\1.exe' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\aupair_7f155fe43f519ab3a6bb116265f90877.jpg' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\aupair_7f155fe43f519ab3a6bb116265f90877.jpg
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\1.exe