Technical Information
Modifies file system
Creates the following files
- %TEMP%\ixp000.tmp\install2.exe
- %TEMP%\ixp000.tmp\omgwtf~2.exe
Deletes following files that it created itself
- %TEMP%\ixp000.tmp\omgwtf~2.exe
- %TEMP%\ixp000.tmp\install2.exe
Network activity
Connects to
- '<DNS_SERVER>':53
Miscellaneous
Creates and executes the following
- '%TEMP%\ixp000.tmp\omgwtf~2.exe'
Executes the following
- '<SYSTEM32>\fondue.exe' /enable-feature:NetFx3 /caller-name:mscoreei.dll
- '%TEMP%\ixp000.tmp\omgwtf~2.exe' ' (with hidden window)