Technical Information
Malicious functions:
Executes the following:
- <SYSTEM32>\wbem\wmiadap.exe /R /T
Modifies file system :
Creates the following files:
- <SYSTEM32>\wbem\Performance\WmiApRpl_new.ini
- <SYSTEM32>\pe.dll