Technical Information
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %TEMP%\fgkfhjkdfhkljslkjsgkljhnkljs.lnk
- %APPDATA%\microsoft\sgegkseg23mjl.dll
- %TEMP%\fgkfhjkdfhkljslkjsgkljhnkljs.lnk
- from %APPDATA%\microsoft\sgegkseg23mjl.dll to %TEMP%\dfshim.dll
- from %TEMP%\dfshim.dll to %TEMP%\tmp5b68.tmp
- 'wo###ow.website':443
- 'pk#.goog':80
- http://pk#.goog/gsr1/gsr1.crt
- 'wo###ow.website':443
- DNS ASK wo###ow.website
- DNS ASK pk#.goog
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %TEMP%\fgkfhjkdfhkljslkjsgkljhnkljs.lnk' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%APPDATA%\Microsoft\sgegkseg23mjl.dll"' (with hidden window)
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\dfshim.dll",cleanonlineappcache' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%APPDATA%\Microsoft\sgegkseg23mjl.dll"
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\dfshim.dll",cleanonlineappcache