Technical Information
- %LOCALAPPDATA%\simple_loader\<File name>.exe_url_jwik1c2bdzzp04gibkydomt5ol2105ok\1.0.0.0\doqehyfl.newcfg
- <Current directory>\etfs0jg0o7x43k2y.exe
- from %LOCALAPPDATA%\simple_loader\<File name>.exe_url_jwik1c2bdzzp04gibkydomt5ol2105ok\1.0.0.0\doqehyfl.newcfg to %LOCALAPPDATA%\simple_loader\<File name>.exe_url_jwik1c2bdzzp04gibkydomt5ol2105ok\1.0.0.0\user.config
- <Current directory>\simple-loader.exe
- from <Full path to file> to <Current directory>\simple-loader.exe
- http://mm###9.ct8.pl/vers.txt
- http://mm###9.ct8.pl/simple-loader.exe
- DNS ASK mm###9.ct8.pl
- '<Current directory>\etfs0jg0o7x43k2y.exe'