Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'mongol' = '"%HOMEPATH%\Documents\k.exe"'
- %HOMEPATH%\documents\af.exe
- %HOMEPATH%\documents\k.exe
- %TEMP%\browserautofill
- %TEMP%\browserautofill
- %TEMP%\browserautofill
- 'ma###server.ml':80
- DNS ASK ma###server.ml
- '%HOMEPATH%\documents\k.exe'
- '%HOMEPATH%\documents\af.exe'