Technical Information
Malicious functions:
Executes the following:
- '<SYSTEM32>\cmd.exe' /c %TEMP%\<Virus name>.bat
Modifies file system :
Creates the following files:
- %TEMP%\<Virus name>.bat
- <SYSTEM32>\adodbupd.dat
Deletes itself.
Network activity:
Connects to:
- 'se####bestbiz.com':80
TCP:
HTTP GET requests:
- se####bestbiz.com/vdocert0108.dat
UDP:
- DNS ASK se####bestbiz.com