Technical Information
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '2G8VJ0O06U5FT4V4THBP62881' = '%ALLUSERSPROFILE%\F63362UYZKU6V3OF\2G8VJ0O06U5FT4V4THBP62881.exe'
- %ALLUSERSPROFILE%\f63362uyzku6v3of\2g8vj0o06u5ft4v4thbp62881.exe
- %ALLUSERSPROFILE%\f63362uyzku6v3of\2g8vj0o06u5ft4v4thbp62881.data
- %ALLUSERSPROFILE%\f63362uyzku6v3of\nw_elf.dll
- %ALLUSERSPROFILE%\f63362uyzku6v3of\heisikong.key
- %TEMP%\9a5if5e58\45581ko100him11m.data
- %TEMP%\9a5if5e58\nw_elf.dll
- %TEMP%\9a5if5e58\45581ko100him11m.exe
- %TEMP%\9a5if5e58\heisikong.key
- %TEMP%\9a5if5e58\2ko9j55lwu.exe
- %TEMP%\9a5if5e58\2ko9j55lwu.data
- %ALLUSERSPROFILE%\f63362uyzku6v3of\2g8vj0o06u5ft4v4thbp62881.mac
- %ALLUSERSPROFILE%\f63362uyzku6v3of\heisikong.key
- %TEMP%\9a5if5e58\heisikong.key
- %TEMP%\9a5if5e58\heisikong.key
- '20#.#5.13.92':8080
- '20#.#5.13.92':12345
- http://20#.##.13.92:8080/5.2.0.0/client.dll via 20#.#5.13.92
- '20#.#5.13.92':12345
- '%ALLUSERSPROFILE%\f63362uyzku6v3of\2g8vj0o06u5ft4v4thbp62881.exe'
- '%TEMP%\9a5if5e58\45581ko100him11m.exe'
- '%TEMP%\9a5if5e58\2ko9j55lwu.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ver' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ver