Technical Information
- [<HKLM>\System\CurrentControlSet\Services\word] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\word] 'ImagePath' = '<SYSTEM32>\svchost.exe -k word'
- [<HKLM>\SYSTEM\CurrentControlSet\Services\word\Parameters\] 'ServiceDll' = '%ProgramFiles(x86)%\IRAT\IRAT.rmvb'
- 'word' <SYSTEM32>\svchost.exe -k word
- Handler for all processes: %ProgramFiles(x86)%\irat\irat.rmvb
- %ProgramFiles(x86)%\irat\irat.rmvb
- %TEMP%\1147324.bat
- %ProgramFiles(x86)%\irat\irat.rmvb
- 'gi####iend.3322.org':82
- DNS ASK gi####iend.3322.org
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\\1147324.bat' (with hidden window)
- '%WINDIR%\syswow64\svchost.exe' -k word
- '%WINDIR%\syswow64\cmd.exe' /c %TEMP%\\1147324.bat