Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'Chrome' = '%APPDATA%\chromez\chrome.exe'
- chrome.exe
- %APPDATA%\chromez\chrome.exe
- http://bz##p.xyz/cream/stagnet.bin
- DNS ASK bz##p.xyz
- DNS ASK st##a.cc
- '%APPDATA%\chromez\chrome.exe' -m "<Full path to file>"