Technical Information
- <SYSTEM32>\tasks\iexplore
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] 'LowRiskFileTypes' = '.exe;.bat;.cmd;.vbs'
- %TEMP%\fixauto.exe
- %APPDATA%\iexplore.exe
- %TEMP%\tmp2de3.tmp.bat
- nul
- 'se####.b92dt.com':63979
- http://fr##.##meanddate.com/clock/i3jl68nm/n246/tlir/tt0/tw0/tm3/th1
- DNS ASK ut#####.colorado.edu
- DNS ASK ti##.ien.it
- DNS ASK ti##.nist.gov
- DNS ASK pt###me1.ptb.de
- DNS ASK fr##.##meanddate.com
- DNS ASK sv##uto.com
- DNS ASK se####.b92dt.com
- ClassName: 'Sword3 Class' WindowName: ''
- '%TEMP%\fixauto.exe'
- '%APPDATA%\iexplore.exe'
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "iexplore" /tr '"%APPDATA%\iexplore.exe"' & exit' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c schtasks /create /f /sc onlogon /rl highest /tn "iexplore" /tr '"%APPDATA%\iexplore.exe"' & exit
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\tmp2DE3.tmp.bat""
- '%WINDIR%\syswow64\schtasks.exe' /create /f /sc onlogon /rl highest /tn "iexplore" /tr '"%APPDATA%\iexplore.exe"'
- '%WINDIR%\syswow64\timeout.exe' 3