Technical Information
Malicious functions:
Executes the following:
- <SYSTEM32>\cmd.exe /c ""%WINDIR%\Temp\temp12829.bat" "
Modifies file system :
Creates the following files:
- %WINDIR%\Temp\temp12829.bat
Deletes itself.
Network activity:
Connects to:
- '46.##6.163.10':6667