Technical Information
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Unwigged' = '%TEMP%\tumidhjrnepun\Morningsu.vbs'
- '' (downloaded from the Internet)
- '%APPDATA%\vbc.exe'
- %WINDIR%\explorer.exe
- firefox.exe
- iexplore.exe process, wininet.dll module
- firefox.exe process, nss3.dll module
- %APPDATA%\vbc.exe
- %TEMP%\tumidhjrnepun\morningsu.exe
- %TEMP%\tumidhjrnepun\morningsu.vbs
- %TEMP%\tumidhjrnepun\morningsu.exe
- http://dn#####pingservices.com/css/fonts/files/JHG9/win98cp.exe
- DNS ASK dn#####pingservices.com
- DNS ASK wt####nsit.com.sg
- '%TEMP%\tumidhjrnepun\morningsu.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\rundll32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\tumidhjrnepun\Morningsu.exe"