Technical Information
- %LOCALAPPDATA%\simple_loader\<File name>.exe_url_0waha2mfrl5vadn31nxhonat3mlmaiat\1.0.0.0\2luqulbu.newcfg
- <Current directory>\t51pngnxhotcjr3t.exe
- from %LOCALAPPDATA%\simple_loader\<File name>.exe_url_0waha2mfrl5vadn31nxhonat3mlmaiat\1.0.0.0\2luqulbu.newcfg to %LOCALAPPDATA%\simple_loader\<File name>.exe_url_0waha2mfrl5vadn31nxhonat3mlmaiat\1.0.0.0\user.config
- <Current directory>\simple-loader.exe
- from <Full path to file> to <Current directory>\simple-loader.exe
- http://mm###9.ct8.pl/vers.txt
- http://mm###9.ct8.pl/simple-loader.exe
- DNS ASK mm###9.ct8.pl
- '<Current directory>\t51pngnxhotcjr3t.exe'