Technical Information
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Temp9uij23hnguiseghwfgj8932hgkhwgsdkljh824g.lnk
- %ALLUSERSPROFILE%\identities\dddfhj349hjlf20ghjsajf32.dll
- %LOCALAPPDATA%\temp9uij23hnguiseghwfgj8932hgkhwgsdkljh824g.lnk
- <Current directory>\8d211000
- from %ALLUSERSPROFILE%\identities\dddfhj349hjlf20ghjsajf32.dll to %TEMP%\sas.dll
- from %TEMP%\sas.dll to %TEMP%\tmpe291.tmp
- <PATH_SAMPLE>.xls
- DNS ASK si####fymedia.pw
- '<SYSTEM32>\rundll32.exe' shell32.dll,ShellExec_RunDLL %LOCALAPPDATA%\Temp9uij23hnguiseghwfgj8932hgkhwgsdkljh824g.lnk' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%ALLUSERSPROFILE%\Identities\dddfhj349hjlf20ghjsajf32.dll"' (with hidden window)
- '<SYSTEM32>\regsvr32.exe' /u /s "%ALLUSERSPROFILE%\Identities\dddfhj349hjlf20ghjsajf32.dll"
- '%WINDIR%\syswow64\rundll32.exe' "%TEMP%\sas.dll",SendSAS