Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft' = '%TEMP%\aero.exe'
- %TEMP%\log.txt
- %TEMP%\temp.bat
- from <Full path to file> to %TEMP%\aero.exe
- '62.##9.27.197':80
- '%WINDIR%\syswow64\cmd.exe' /c temp.bat' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c temp.bat
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Microsoft" /t REG_SZ /F /D %TEMP%\aero.exe