Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Win32.HLLW.Autoruner2.52932

Added to the Dr.Web virus database: 2019-07-22

Virus description added:

Technical Information

To ensure autorun and distribution
Creates or modifies the following files
  • %WINDIR%\tasks\moduleico.job
Creates the following files on removable media
  • <Drive name for removable media>:\read.me
  • <Drive name for removable media>:\pubnet_855.rtf.lnk
  • <Drive name for removable media>:\tapi\dels13110.doc
  • <Drive name for removable media>:\lisp_success.doc.lnk
  • <Drive name for removable media>:\tapi\dels19428.doc
  • <Drive name for removable media>:\krsweden.rtf.lnk
  • <Drive name for removable media>:\tapi\dels16029.doc
  • <Drive name for removable media>:\february_catalogue__2015.doc.lnk
  • <Drive name for removable media>:\tapi\dels23538.doc
  • <Drive name for removable media>:\waterlandhealthkano.rtf.lnk
  • <Drive name for removable media>:\tapi\dels5589.doc
  • <Drive name for removable media>:\weeklysheet1215.doc.lnk
  • <Drive name for removable media>:\tapi\dels28180.doc
  • <Drive name for removable media>:\fungalnameauthors.rtf.lnk
  • <Drive name for removable media>:\tapi\dels23800.doc
  • <Drive name for removable media>:\cveuropeo.doc.lnk
  • <Drive name for removable media>:\tapi\dels15411.doc
  • <Drive name for removable media>:\router_manual.rtf.lnk
  • <Drive name for removable media>:\tapi\dels4506.doc
  • <Drive name for removable media>:\glidescope_review_rev_010.docx.lnk
  • <Drive name for removable media>:\tapi\dels561.doc
  • <Drive name for removable media>:\phytoremediation.rtf.lnk
  • <Drive name for removable media>:\tapi\dels31119.doc
  • <Drive name for removable media>:\documents.lnk
  • <Drive name for removable media>:\tapi\dels30738.doc
  • <Drive name for removable media>:\aoc_saq_d_v3_merchant.docx.lnk
Malicious functions
Executes the following
  • '<SYSTEM32>\taskkill.exe' /f /im "mshta.exe"
Modifies file system
Creates the following files
  • %TEMP%\7zipsfx.000\wariable.cmd
  • %TEMP%\7zipsfx.001\fjpeh
  • %TEMP%\7zipsfx.001\officemodule.exe
  • %TEMP%\7zipsfx.001\mshta.cmd
  • %TEMP%\7zipsfx.001\id.cmd
  • %TEMP%\7zipsfx.001\wget.cmd
  • %TEMP%\7zipsfx.001\sosun.cmd
  • %TEMP%\7zipsfx.001\usb.cmd
  • %TEMP%\7zipsfx.001\statistic.cmd
  • %TEMP%\7zipsfx.001\kills.cmd
  • %TEMP%\7zipsfx.001\wariables.cmd
  • %TEMP%\7zipsfx.001\wariable.cmd
  • %TEMP%\7zipsfx.001\hetns.exe
  • %TEMP%\7zipsfx.000\ukywc
  • %TEMP%\7zipsfx.000\hetns.exe
  • %TEMP%\7zipsfx.000\fjpeh
  • %TEMP%\7zipsfx.000\officemodule.exe
  • %TEMP%\7zipsfx.000\mshta.cmd
  • %TEMP%\7zipsfx.000\id.cmd
  • %TEMP%\7zipsfx.000\wget.cmd
  • %TEMP%\7zipsfx.000\sosun.cmd
  • %TEMP%\7zipsfx.000\usb.cmd
  • %TEMP%\7zipsfx.000\statistic.cmd
  • %TEMP%\7zipsfx.000\kills.cmd
  • %TEMP%\7zipsfx.000\wariables.cmd
  • %WINDIR%\microsoft\office\module\moduleico.exe
  • %TEMP%\7zipsfx.001\ukywc
Sets the 'hidden' attribute to the following files
  • <Drive name for removable media>:\read.me
  • <Drive name for removable media>:\tapi\dels31119.doc
  • <Drive name for removable media>:\tapi\dels561.doc
  • <Drive name for removable media>:\tapi\dels4506.doc
  • <Drive name for removable media>:\tapi\dels15411.doc
  • <Drive name for removable media>:\tapi\dels23800.doc
  • <Drive name for removable media>:\tapi\dels28180.doc
  • <Drive name for removable media>:\tapi\dels5589.doc
  • <Drive name for removable media>:\tapi\dels23538.doc
  • <Drive name for removable media>:\tapi\dels16029.doc
  • <Drive name for removable media>:\tapi\dels19428.doc
  • <Drive name for removable media>:\tapi\dels13110.doc
  • <Drive name for removable media>:\tapi\dels30738.doc
Deletes the following files
  • %TEMP%\7zipsfx.000\ukywc
  • %TEMP%\7zipsfx.000\fjpeh
  • %TEMP%\7zipsfx.000\hetns.exe
  • %TEMP%\7zipsfx.000\id.cmd
  • %TEMP%\7zipsfx.000\kills.cmd
  • %TEMP%\7zipsfx.000\mshta.cmd
  • %TEMP%\7zipsfx.000\officemodule.exe
  • %TEMP%\7zipsfx.000\ohjtt.cmd
  • %TEMP%\7zipsfx.000\statistic.cmd
  • %TEMP%\7zipsfx.000\usb.cmd
  • %TEMP%\7zipsfx.000\wariable.cmd
  • %TEMP%\7zipsfx.000\wariables.cmd
  • %TEMP%\7zipsfx.000\wget.cmd
  • %TEMP%\7zipsfx.001\ukywc
Moves the following files
  • from %TEMP%\7zipsfx.000\sosun.cmd to %TEMP%\7zipsfx.000\ohjtt.cmd
  • from %TEMP%\7zipsfx.001\sosun.cmd to %TEMP%\7zipsfx.001\ohjtt.cmd
Miscellaneous
Searches for the following windows
  • ClassName: '' WindowName: ''
Creates and executes the following
  • '%WINDIR%\microsoft\office\module\moduleico.exe'
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.000\Wariable.cmd" sar"' (with hidden window)
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.001\Wariable.cmd" sar"' (with hidden window)
Executes the following
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.000\Wariable.cmd" sar"
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\phytoremediation.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI...
  • '<SYSTEM32>\cmd.exe' /c dir /b /s /a "<Drive name for removable media>:\*.doc"
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\glidescope_review_rev_010.docx.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\router_manual.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\DE...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\cveuropeo.doc.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\DELS15...
  • '<SYSTEM32>\cmd.exe' /c dir /b/s "<Drive name for removable media>:\*.lnk"
  • '<SYSTEM32>\attrib.exe' +h <Drive name for removable media>:\read.me /s
  • '<SYSTEM32>\attrib.exe' +h <Drive name for removable media>:\TAPI /d /s
  • '<SYSTEM32>\attrib.exe' +h <Drive name for removable media>:\TAPI\DELS* /s
  • '<SYSTEM32>\ping.exe' 8.8.8.8
  • '<SYSTEM32>\find.exe' /i "TTL="
  • '<SYSTEM32>\reg.exe' QUERY "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v Hidden
  • '<SYSTEM32>\cmd.exe' /c tasklist /FI "IMAGENAME eq ModuleICO.exe" | find /C "ModuleICO.exe"
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\pubnet_855.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\DELS1...
  • '<SYSTEM32>\tasklist.exe' /FI "IMAGENAME eq ModuleICO.exe"
  • '<SYSTEM32>\cmd.exe' /c ""%TEMP%\7ZipSfx.001\Wariable.cmd" sar"
  • '<SYSTEM32>\cmd.exe' /c tasklist /fi "PID eq 1468 " /fo csv
  • '<SYSTEM32>\tasklist.exe' /fi "PID eq 1468" /fo csv
  • '<SYSTEM32>\cmd.exe' /c wmic process where "Name='ModuleICO.exe'" get ExecutablePath /value| findstr
  • '<SYSTEM32>\wbem\wmic.exe' process where "Name='ModuleICO.exe'" get ExecutablePath /value
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\fungalnameauthors.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAP...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\weeklysheet1215.doc.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\WaterLandHealthKano.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \T...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\february_catalogue__2015.doc.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\krsweden.rtf.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\DELS160...
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\lisp_success.doc.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C \TAPI\DEL...
  • '<SYSTEM32>\cmd.exe' /c dir /b /s /a "<Drive name for removable media>:\*.rtf"
  • '<SYSTEM32>\find.exe' "0x2"
  • '<SYSTEM32>\cmd.exe' /c dir /s /b %WINDIR%\Installer\wordicon.exe
  • '<SYSTEM32>\cmd.exe' /c vol c
  • '<SYSTEM32>\cmd.exe' /c wmic process get parentprocessid, commandline /value
  • '<SYSTEM32>\wbem\wmic.exe' process get parentprocessid, commandline /value
  • '<SYSTEM32>\cmd.exe' /c tasklist /fi "PID eq 3868 " /fo csv
  • '<SYSTEM32>\tasklist.exe' /fi "PID eq 3868" /fo csv
  • '<SYSTEM32>\cmd.exe' /c wmic process where "Name='<File name>.exe'" get ExecutablePath /value| findstr
  • '<SYSTEM32>\wbem\wmic.exe' process where "Name='<File name>.exe'" get ExecutablePath /value
  • '<SYSTEM32>\findstr.exe'
  • '<SYSTEM32>\cmd.exe' /c tasklist /nh /fi "imagename eq ModuleICO.exe" | find /c "ModuleICO.exe"
  • '<SYSTEM32>\find.exe' /c "ModuleICO.exe"
  • '<SYSTEM32>\tasklist.exe' /nh /fi "imagename eq ModuleICO.exe"
  • '<SYSTEM32>\cmd.exe' /S /D /c" ver "
  • '<SYSTEM32>\find.exe' /i "5.1"
  • '<SYSTEM32>\systeminfo.exe'
  • '<SYSTEM32>\cmd.exe' /c dir /b/s "<Drive name for removable media>:\*.exe"
  • '<SYSTEM32>\schtasks.exe' /Query /tn ModuleICO
  • '<SYSTEM32>\schtasks.exe' /Create /sc MINUTE /mo 12 /ru "SYSTEM" /tn ModuleICO /tr "%WINDIR%\Microsoft\Office\Module\ModuleICO.exe"
  • '<SYSTEM32>\cmd.exe' /c WMIC LogicalDisk Where (DriveType=2 And MediaType=NULL) Get Name,VolumeSerialNumber /Value|Find "="
  • '<SYSTEM32>\wbem\wmic.exe' LogicalDisk Where (DriveType=2 And MediaType=NULL) Get Name,VolumeSerialNumber /Value
  • '<SYSTEM32>\find.exe' "="
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\Documents.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C %WINDIR%\explore...
  • '<SYSTEM32>\attrib.exe' +h "<Drive name for removable media>:\read.me"
  • '<SYSTEM32>\find.exe' "mshta.exe"
  • '<SYSTEM32>\tasklist.exe'
  • '<SYSTEM32>\attrib.exe' +h <Drive name for removable media>:\TAPI
  • '<SYSTEM32>\attrib.exe' -h "<Drive name for removable media>:\*.*" /s
  • '<SYSTEM32>\cmd.exe' /c dir /b/s <Drive name for removable media>:\read.me
  • '<SYSTEM32>\cmd.exe' /c dir /b/s "<Drive name for removable media>:\*.lnk.lnk"
  • '<SYSTEM32>\mshta.exe' vbscript:Execute("Set y=CreateObject(""WScript.Shell"").CreateShortcut(""<Drive name for removable media>:\aoc_saq_d_v3_merchant.docx.lnk""):y.TargetPath=""<SYSTEM32>\cmd.exe"":y.Arguments=""/C...