Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'D5JHBNBH5' = 'cmd.exe /c reg.exe add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v BLIYN3GRYC /t REG_SZ /d "regsvr32.exe -s %TEM...
- %TEMP%\b8b51a1.dll
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s <Full path to file> RJI0Q
- '<SYSTEM32>\ping.exe' 8.#.7.7 -n 2
- '<SYSTEM32>\regsvr32.exe' -s <Full path to file> RJI0Q
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s %TEMP%\B8B51A1.dll F2AA
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\B8B51A1.dll F2AA
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s %TEMP%\B8B51A1.dll NE3X4U
- '<SYSTEM32>\regsvr32.exe' -s %TEMP%\B8B51A1.dll NE3X4U
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s <Full path to file> RJI0Q' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s %TEMP%\B8B51A1.dll F2AA' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ping 8.#.7.7 -n 2 & start regsvr32.exe -s %TEMP%\B8B51A1.dll NE3X4U' (with hidden window)