Technical Information
- %WINDIR%\syswow64\msiexec.exe
- %TEMP%\tmp.txt
- %APPDATA%\mati\axyze.exe
- %TEMP%\ulerow.tmp-shm
- %TEMP%\ulerow.tmp-shm
- http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
- DNS ASK no###eets.net
- DNS ASK microsoft.com
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /all' (with hidden window)
- '%WINDIR%\syswow64\wbem\wmic.exe' /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net config workstation' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c net view /all' (with hidden window)
- '%WINDIR%\syswow64\msiexec.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ipconfig /all
- '%WINDIR%\syswow64\wbem\wmic.exe' /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List
- '%WINDIR%\syswow64\ipconfig.exe' /all
- '%WINDIR%\syswow64\cmd.exe' /c net config workstation
- '%WINDIR%\syswow64\net.exe' config workstation
- '%WINDIR%\syswow64\net1.exe' config workstation
- '%WINDIR%\syswow64\cmd.exe' /c net view /all
- '%WINDIR%\syswow64\net.exe' view /all