Execution of Malware

  1. Whenever the system is rebooted, the following actions are performed:
    1. The LNK file is executed by the operating system from startup folder
    2. The LNK file executes the BAT file
    3. The BAT file starts the file with the 331aa3f extension
    4. The 331aa3f extension registry value forwards to the 33eb18 extension registry value
    5. Shell | Open | Command is executed, and the first malicious script runs

This provides the malware with an opportunity to start automatically at system startup.

  1. As can be seen in the following screenshot, MSHTA is a legitimate Windows executable that supports running JavaScript files. This feature is frequently exploited by malware authors and used for running encoded/encrypted malicious JavaScript files ...

Get Learn Social Engineering now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.