- Whenever the system is rebooted, the following actions are performed:
- The LNK file is executed by the operating system from startup folder
- The LNK file executes the BAT file
- The BAT file starts the file with the 331aa3f extension
- The 331aa3f extension registry value forwards to the 33eb18 extension registry value
- Shell | Open | Command is executed, and the first malicious script runs
This provides the malware with an opportunity to start automatically at system startup.
- As can be seen in the following screenshot, MSHTA is a legitimate Windows executable that supports running JavaScript files. This feature is frequently exploited by malware authors and used for running encoded/encrypted malicious JavaScript files ...