Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Sitef Monitoring' = '<Full path to file>'
- '<SYSTEM32>\net1.exe' user user !@c4rnic3ir0!@ /add
- '<SYSTEM32>\net.exe' user user !@c4rnic3ir0!@ /add
- '<SYSTEM32>\cmd.exe'
- 'zu####rack2.esy.es':80
- '19#.#54.226.19':1
- 'wp#d':80
- 'ch####p.dyndns.org':80
- http://ch####p.dyndns.org/
- http://11#.#11.111.1/wpad.dat via wp#d
- http://zu####rack2.esy.es/PhpDumps.php
- DNS ASK zu####rack2.esy.es
- DNS ASK ch####p.dyndns.org
- DNS ASK wp#d