Technical Information
- %TEMP%\windos\code.exetext
- %TEMP%\windos\code.exe
- nul
- %TEMP%\windos\code.exe
- %TEMP%\windos\code.exetext
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK microsoft.com
- '%TEMP%\windos\code.exe'
- '%WINDIR%\syswow64\certutil.exe' /decode "%TEMP%\windos\code.exetext" "%TEMP%\windos\code.exe"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\certutil.exe' /decode "%TEMP%\windos\code.exetext" "%TEMP%\windos\code.exe"
- '%WINDIR%\syswow64\cmd.exe' /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del "<Full path to file>"
- '%WINDIR%\syswow64\ping.exe' 1.1.1.1 -n 1 -w 3000