Technical Information
Malicious functions
Injects code into
the following system processes:
- %WINDIR%\syswow64\svchost.exe
Modifies file system
Creates the following files
- %TEMP%\explore.exe
Network activity
Connects to
- 'localhost':1604
Miscellaneous
Creates and executes the following
- '%TEMP%\explore.exe'
Executes the following
- '%WINDIR%\syswow64\svchost.exe'