Technical Information
Malicious functions:
Executes the following:
- <SYSTEM32>\net1.exe stop SharedAccess
- <SYSTEM32>\net.exe stop SharedAccess
Modifies file system :
Creates the following files:
- %TEMP%\80EB2F5C
Miscellaneous:
Searches for the following windows:
- ClassName: 'Shell_TrayWnd' WindowName: ''